CVE-2026-33941 is a high-severity (CVSS 8.2) arbitrary JavaScript injection vulnerability affecting Handlebars.js versions 4.0.0 through 4.7.8. The Handlebars CLI precompiler concatenates unescaped user-controlled strings, such as template filenames and CLI options, directly into the generated JavaScript. This allows an attacker with local access or influence over CLI arguments to inject malicious JavaScript, which executes when the bundle is loaded, leading to high impact on confidentiality, integrity, and availability. The attack requires low privileges and user interaction. Currently, there is no evidence of active exploitation or publicly available exploit code, though the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.7.9CPE matchmatch criteria | cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.