Handlebars
Vendor:
First CVE: Sep 30, 2020 · Active for 5 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Handlebars over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2020
5 years ago
Most Recent CVE
Mar 27, 2026
120 days ago
CVE Severity & Scoring
Handlebars10 CVEs
10%
60%
30%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High4 (40.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33937CRITICAL Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition t | Mar 27, 2026 | 9.8 | 40 | NO | NO |
CVE-2021-23383CRITICAL The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. | May 4, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-23369CRITICAL The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source. | Apr 12, 2021 | 9.8 | 33 | NO | NO |
CVE-2026-33941HIGH Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler. | Mar 27, 2026 | 8.2 | 32 | NO | NO |
CVE-2026-33938HIGH Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data | Mar 27, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-33940HIGH Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all condi | Mar 27, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-33939HIGH Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an | Mar 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2019-20920HIGH Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templat | Sep 30, 2020 | 8.1 | 26 | NO | NO |
CVE-2019-20922HIGH Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templa | Sep 30, 2020 | 7.5 | 25 | NO | NO |
CVE-2026-33916MEDIUM Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names | Mar 27, 2026 | 4.7 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Handlebars
Top CWEs
Versions
No cataloged versions.