Handlebars

Vendor:

First CVE: Sep 30, 2020 · Active for 5 years

10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Handlebars over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2020
5 years ago
Most Recent CVE
Mar 27, 2026
120 days ago

CVE Severity & Scoring

Handlebars10 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High4 (40.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition t
Mar 27, 20269.840NONO
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
May 4, 20219.833NONO
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Apr 12, 20219.833NONO
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.
Mar 27, 20268.232NONO
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data
Mar 27, 20268.132NONO
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all condi
Mar 27, 20268.131NONO
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an
Mar 27, 20267.530NONO
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templat
Sep 30, 20208.126NONO
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templa
Sep 30, 20207.525NONO
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names
Mar 27, 20264.719NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Handlebars

Top CWEs

Versions

No cataloged versions.