No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10. | |
| Title | Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates | |
| Weaknesses | CWE-116 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T19:48:02.050Z
Reserved: 2026-10-06T16:49:40.590Z
Link: CVE-2026-106444
Updated: 2026-10-06T19:47:56.780Z
Status : Received
Published: 2026-10-06T20:17:26.130
Modified: 2026-10-06T20:17:26.130
Link: CVE-2026-106444
No data.
OpenCVE Enrichment
No data.
-
CWE-116
Improper Encoding or Escaping of Output