CVE-2026-33940 affects Handlebars versions 4.0.0 through 4.7.8, where a crafted object in the template context can bypass partial resolution, leading to arbitrary command execution on the server within handlebarsjs and handlebars libraries. Rated High with a CVSS score of 8.1, this vulnerability has a network attack vector but requires high attack complexity, as an adversary needs to control a value returned by a dynamic partial lookup to achieve full confidentiality, integrity, and availability compromise. There is currently no evidence of active exploitation (KEV) or public exploit code available. While community discussion exists regarding the CVE and its fix in version 4.7.9, its Exploit Prediction Scoring System (EPSS) score is very low, indicating a low likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.7.9CPE matchmatch criteria | cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.