CVE-2026-33937 is a critical Remote Code Execution (RCE) vulnerability affecting Handlebars.js versions 4.0.0 through 4.7.8. It stems from improper sanitization in the `Handlebars.compile()` function, allowing an attacker to inject and execute arbitrary JavaScript by supplying a crafted Abstract Syntax Tree (AST). With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network without authentication or user interaction, leading to full compromise of affected systems. While there is no known active exploitation or public exploit code available, the vulnerability has garnered community attention, and patches are available in version 4.7.9. Workarounds include validating input type or using the runtime-only build.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.7.9CPE matchmatch criteria | cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.