<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Handlebars (V4.0.0 to V4.7.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/handlebars-v4.0.0-to-v4.7.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:25:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/handlebars-v4.0.0-to-v4.7.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Handlebars Prototype Pollution and RCE via Function Constructor Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-10-handlebars-rce/</link><pubDate>Thu, 08 Oct 2026 19:25:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-handlebars-rce/</guid><description>Handlebars (v4.0.0-4.7.9) is vulnerable to a prototype-access deny list bypass where own property checks permit the retrieval of the Function constructor, enabling remote code execution when allowProtoMethodsByDefault is enabled.</description><content:encoded><![CDATA[<p>Handlebars (v4.0.0 through v4.7.9) contains a critical vulnerability (CVE-2026-106445) involving the mishandling of prototype properties. The library's <code>lookupProperty</code> function incorrectly trusts properties identified as &quot;own&quot; properties, effectively bypassing the security deny list designed to block access to dangerous methods like <code>constructor</code>. In environments where <code>allowProtoMethodsByDefault</code> is set to <code>true</code> when compiling templates, an attacker capable of providing a Handlebars template can navigate the prototype chain to reach <code>Function.prototype</code>. Because the <code>constructor</code> property is an own property of prototype objects, the engine returns it without evaluating the deny list. This grants the attacker access to the JavaScript <code>Function</code> constructor, which can then be leveraged to create and execute arbitrary code on the server-side runtime.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application rendering Handlebars templates where <code>allowProtoMethodsByDefault</code> is configured as <code>true</code>.</li>
<li>Attacker submits a malicious Handlebars template string to the application's template rendering engine.</li>
<li>Attacker uses <code>{{lookup myFunction &quot;__proto__&quot;}}</code> or similar expressions to navigate to <code>Function.prototype</code>.</li>
<li>Attacker invokes <code>{{lookup (lookup myFunction &quot;__proto__&quot;) &quot;constructor&quot;}}</code>, exploiting the <code>hasOwnProperty</code> trust in <code>lookupProperty</code> to retrieve the <code>Function</code> object.</li>
<li>Attacker pushes the <code>Function</code> object into an array accessible within the template context via <code>{{lookup &quot;&quot; (@root.a.push ...)}}</code>.</li>
<li>Attacker uses Handlebars helper directives (e.g., <code>#each</code> or <code>#with</code>) to invoke the retrieved <code>Function</code> constructor.</li>
<li>The <code>Function</code> constructor evaluates an attacker-supplied string as JavaScript, leading to Remote Code Execution (RCE) in the Node.js runtime.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full Remote Code Execution (RCE) on the server running the Node.js application. This allows an attacker to execute arbitrary system commands, potentially resulting in data exfiltration, service disruption, or further compromise of the host infrastructure. The vulnerability affects all versions of Handlebars between 4.0.0 and 4.7.9.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately identify all application codebases utilizing Handlebars where the <code>allowProtoMethodsByDefault</code> option is set to <code>true</code>.</li>
<li>Set <code>allowProtoMethodsByDefault</code> to <code>false</code> in all template compilation configurations until the environment can be patched or verified as secure.</li>
<li>Upgrade the Handlebars dependency to a version where CVE-2026-106445 is remediated.</li>
<li>Implement strict server-side validation and sanitization for any user-supplied strings that are subsequently rendered by the Handlebars template engine.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>prototype-pollution</category><category>javascript-injection</category></item></channel></rss>