Description
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 30 Sep 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory. | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-30T00:55:19.940Z
Reserved: 2026-09-30T00:55:19.173Z
Link: CVE-2026-103088
No data.
Status : Deferred
Published: 2026-09-30T02:16:57.203
Modified: 2026-09-30T02:16:57.340
Link: CVE-2026-103088
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-24
Path Traversal: '../filedir'