CVE-2026-33916

MEDIUM

Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Title source: cna
STIX 2.1

Description

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates and reduces the attack surface.

Scores

CVSS v3 4.7
EPSS 0.0005
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1321 CWE-79
Status published
Products (3)
handlebarsjs/handlebars 4.0.0 - 4.7.9
handlebars-lang/handlebars.js >= 4.0.0, < 4.7.9
npm/handlebars 4.0.0 - 4.7.9npm
Published Mar 27, 2026
Tracked Since Mar 29, 2026