Product
Handlebars (v4.0.0-4.7.9) is vulnerable to a prototype-access deny list bypass where own property checks permit the retrieval of the Function constructor, enabling remote code execution when allowProtoMethodsByDefault is enabled.