CVE-2019-19919 is a critical Prototype Pollution vulnerability in Handlebars.js versions prior to 4.3.0, affecting products like Tenable.sc. This flaw allows attackers to manipulate object prototypes and execute arbitrary code via crafted payloads, posing a severe risk with a CVSS score of 9.8. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.6CPE matchmatch criteria | cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.6:-:*:*:*:node.js:*:* | ||
1.0.7CPE matchmatch criteria | cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.7:-:*:*:*:node.js:*:* | ||
1.0.8CPE matchmatch criteria | cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.8:-:*:*:*:node.js:*:* | ||
1.0.9CPE matchmatch criteria | cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.9:-:*:*:*:node.js:*:* | ||
1.0.10CPE matchmatch criteria | cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.10:-:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.