Skip to content
Threat Feed
critical advisory

Handlebars Prototype Pollution and RCE via Function Constructor Bypass

Handlebars (v4.0.0-4.7.9) is vulnerable to a prototype-access deny list bypass where own property checks permit the retrieval of the Function constructor, enabling remote code execution when allowProtoMethodsByDefault is enabled.

CVE search metadata

CVE search record: CVE-2026-106445. EPSS: 0.41%. KEV: no. Product: handlebars (v4.0.0 to v4.7.9). Brief: Handlebars Prototype Pollution and RCE via Function Constructor Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-10-handlebars-rce/

Handlebars (v4.0.0 through v4.7.9) contains a critical vulnerability (CVE-2026-106445) involving the mishandling of prototype properties. The library's lookupProperty function incorrectly trusts properties identified as "own" properties, effectively bypassing the security deny list designed to block access to dangerous methods like constructor. In environments where allowProtoMethodsByDefault is set to true when compiling templates, an attacker capable of providing a Handlebars template can navigate the prototype chain to reach Function.prototype. Because the constructor property is an own property of prototype objects, the engine returns it without evaluating the deny list. This grants the attacker access to the JavaScript Function constructor, which can then be leveraged to create and execute arbitrary code on the server-side runtime.

Attack Chain

  1. Attacker identifies a target application rendering Handlebars templates where allowProtoMethodsByDefault is configured as true.
  2. Attacker submits a malicious Handlebars template string to the application's template rendering engine.
  3. Attacker uses {{lookup myFunction "__proto__"}} or similar expressions to navigate to Function.prototype.
  4. Attacker invokes {{lookup (lookup myFunction "__proto__") "constructor"}}, exploiting the hasOwnProperty trust in lookupProperty to retrieve the Function object.
  5. Attacker pushes the Function object into an array accessible within the template context via {{lookup "" (@root.a.push ...)}}.
  6. Attacker uses Handlebars helper directives (e.g., #each or #with) to invoke the retrieved Function constructor.
  7. The Function constructor evaluates an attacker-supplied string as JavaScript, leading to Remote Code Execution (RCE) in the Node.js runtime.

Impact

Successful exploitation leads to full Remote Code Execution (RCE) on the server running the Node.js application. This allows an attacker to execute arbitrary system commands, potentially resulting in data exfiltration, service disruption, or further compromise of the host infrastructure. The vulnerability affects all versions of Handlebars between 4.0.0 and 4.7.9.

Recommendation

  • Immediately identify all application codebases utilizing Handlebars where the allowProtoMethodsByDefault option is set to true.
  • Set allowProtoMethodsByDefault to false in all template compilation configurations until the environment can be patched or verified as secure.
  • Upgrade the Handlebars dependency to a version where CVE-2026-106445 is remediated.
  • Implement strict server-side validation and sanitization for any user-supplied strings that are subsequently rendered by the Handlebars template engine.

Immediate actions

Disable allowProtoMethodsByDefault in all Handlebars template configurations

DevOps 24h

Mitigations

Upgrade handlebars to 4.7.10 or later

immediate IT Operations

CVE-2026-106445