{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/handlebars-v4.0.0-to-v4.7.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-106445"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["handlebars (v4.0.0 to v4.7.9)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","prototype-pollution","javascript-injection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eHandlebars (v4.0.0 through v4.7.9) contains a critical vulnerability (CVE-2026-106445) involving the mishandling of prototype properties. The library's \u003ccode\u003elookupProperty\u003c/code\u003e function incorrectly trusts properties identified as \u0026quot;own\u0026quot; properties, effectively bypassing the security deny list designed to block access to dangerous methods like \u003ccode\u003econstructor\u003c/code\u003e. In environments where \u003ccode\u003eallowProtoMethodsByDefault\u003c/code\u003e is set to \u003ccode\u003etrue\u003c/code\u003e when compiling templates, an attacker capable of providing a Handlebars template can navigate the prototype chain to reach \u003ccode\u003eFunction.prototype\u003c/code\u003e. Because the \u003ccode\u003econstructor\u003c/code\u003e property is an own property of prototype objects, the engine returns it without evaluating the deny list. This grants the attacker access to the JavaScript \u003ccode\u003eFunction\u003c/code\u003e constructor, which can then be leveraged to create and execute arbitrary code on the server-side runtime.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application rendering Handlebars templates where \u003ccode\u003eallowProtoMethodsByDefault\u003c/code\u003e is configured as \u003ccode\u003etrue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker submits a malicious Handlebars template string to the application's template rendering engine.\u003c/li\u003e\n\u003cli\u003eAttacker uses \u003ccode\u003e{{lookup myFunction \u0026quot;__proto__\u0026quot;}}\u003c/code\u003e or similar expressions to navigate to \u003ccode\u003eFunction.prototype\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker invokes \u003ccode\u003e{{lookup (lookup myFunction \u0026quot;__proto__\u0026quot;) \u0026quot;constructor\u0026quot;}}\u003c/code\u003e, exploiting the \u003ccode\u003ehasOwnProperty\u003c/code\u003e trust in \u003ccode\u003elookupProperty\u003c/code\u003e to retrieve the \u003ccode\u003eFunction\u003c/code\u003e object.\u003c/li\u003e\n\u003cli\u003eAttacker pushes the \u003ccode\u003eFunction\u003c/code\u003e object into an array accessible within the template context via \u003ccode\u003e{{lookup \u0026quot;\u0026quot; (@root.a.push ...)}}\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker uses Handlebars helper directives (e.g., \u003ccode\u003e#each\u003c/code\u003e or \u003ccode\u003e#with\u003c/code\u003e) to invoke the retrieved \u003ccode\u003eFunction\u003c/code\u003e constructor.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eFunction\u003c/code\u003e constructor evaluates an attacker-supplied string as JavaScript, leading to Remote Code Execution (RCE) in the Node.js runtime.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full Remote Code Execution (RCE) on the server running the Node.js application. This allows an attacker to execute arbitrary system commands, potentially resulting in data exfiltration, service disruption, or further compromise of the host infrastructure. The vulnerability affects all versions of Handlebars between 4.0.0 and 4.7.9.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all application codebases utilizing Handlebars where the \u003ccode\u003eallowProtoMethodsByDefault\u003c/code\u003e option is set to \u003ccode\u003etrue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSet \u003ccode\u003eallowProtoMethodsByDefault\u003c/code\u003e to \u003ccode\u003efalse\u003c/code\u003e in all template compilation configurations until the environment can be patched or verified as secure.\u003c/li\u003e\n\u003cli\u003eUpgrade the Handlebars dependency to a version where CVE-2026-106445 is remediated.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side validation and sanitization for any user-supplied strings that are subsequently rendered by the Handlebars template engine.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:25:27Z","date_published":"2026-10-08T19:25:27Z","id":"https://feed.craftedsignal.io/briefs/2026-10-handlebars-rce/","summary":"Handlebars (v4.0.0-4.7.9) is vulnerable to a prototype-access deny list bypass where own property checks permit the retrieval of the Function constructor, enabling remote code execution when allowProtoMethodsByDefault is enabled.","title":"Handlebars Prototype Pollution and RCE via Function Constructor Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-handlebars-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Handlebars (V4.0.0 to V4.7.9)","version":"https://jsonfeed.org/version/1.1"}