CVE-2021-23383

MEDIUM

handlebars < 4.7.7 - Prototype Pollution via Template Compilation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-23383. PoCs published by fazilbaig1, dn9uy3n.

AI-analyzed exploit summary This repository contains a functional exploit and scanner for CVE-2021-23383, a Prototype Pollution vulnerability in Handlebars versions before 4.7.7. The exploit sends a crafted template payload to trigger the vulnerability, while the scanner checks for vulnerable Handlebars versions.

Description

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

Exploits (2)

nomisec WORKING POC 1 stars
by fazilbaig1 · poc
https://github.com/fazilbaig1/CVE-2021-23383

This repository contains a functional exploit and scanner for CVE-2021-23383, a Prototype Pollution vulnerability in Handlebars versions before 4.7.7. The exploit sends a crafted template payload to trigger the vulnerability, while the scanner checks for vulnerable Handlebars versions.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Handlebars < 4.7.7
No auth needed
Prerequisites: Target server running a vulnerable version of Handlebars · Network access to the target server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER 1 stars
by dn9uy3n · poc
https://github.com/dn9uy3n/Check-CVE-2021-23383

This repository contains a Python script that scans for the presence of vulnerable versions of the Handlebars library (CVE-2021-23383) by checking script tags in a webpage. It does not exploit the vulnerability but detects it by version assessment.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Handlebars library versions < 4.7.7
No auth needed
Prerequisites: Access to the target webpage
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029
Exploit, Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030
Exploit, Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031
Exploit, Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210618-0007/

Scores

CVSS v3 5.6
EPSS 0.0567
EPSS Percentile 90.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-1321
Status published
Products (3)
handlebarsjs/handlebars < 4.7.7
netapp/e-series_performance_analyzer
npm/handlebars 0 - 4.7.7npm
Published May 04, 2021
Tracked Since Feb 18, 2026