CVE-2021-23383

MEDIUM

Handlebars < 4.7.7 - Prototype Pollution

Title source: rule

Description

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

Exploits (2)

nomisec WORKING POC 1 stars
by fazilbaig1 · poc
https://github.com/fazilbaig1/CVE-2021-23383
nomisec SCANNER 1 stars
by dn9uy3n · poc
https://github.com/dn9uy3n/Check-CVE-2021-23383

Scores

CVSS v3 5.6
EPSS 0.0318
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-1321
Status published
Products (3)
handlebarsjs/handlebars < 4.7.7
netapp/e-series_performance_analyzer
npm/handlebars 0 - 4.7.7npm
Published May 04, 2021
Tracked Since Feb 18, 2026