VDB
Sign up
LOW3.7

GHSA-442j-39wm-28r2

Handlebars.js has a Property Access Validation Bypass in container.lookup

Quick fix

GHSA-442j-39wm-28r2 — handlebars: upgrade to the fixed version with the command below.

npm install handlebars@4.7.9

Details

## Summary

In `lib/handlebars/runtime.js`, the `container.lookup()` function uses `container.lookupProperty()` as a gate check to enforce prototype-access controls, but then discards the validated result and performs a second, unguarded property access (`depths[i][name]`). This Time-of-Check Time-of-Use (TOCTOU) pattern means the security check and the actual read are decoupled, and the raw access bypasses any sanitization that `lookupProperty` may perform.

Only relevant when the **compat** compile option is enabled (`{compat: true}`), which activates `depthedLookup` in `lib/handlebars/compiler/javascript-compiler.js`.

## Description

The vulnerable code in `lib/handlebars/runtime.js` (lines 137–144):

```javascript lookup: function (depths, name) { const len = depths.length; for (let i = 0; i < len; i++) { let result = depths[i] && container.lookupProperty(depths[i], name); if (result != null) { return depths[i][name]; // BUG: should be `return result;` } } }, ```

`container.lookupProperty()` (lines 119–136) enforces `hasOwnProperty` checks and `resultIsAllowed()` prototype-access controls. However, `container.lookup()` only uses `lookupProperty` as a boolean gate — if the gate passes (`result != null`), it then performs an independent, raw `depths[i][name]` access that circumvents any transformation or wrapped value that `lookupProperty` may have returned.

## Workarounds

- Avoid enabling `{ compat: true }` when rendering templates that include untrusted data. - Ensure context data objects are plain JSON (no Proxies, no getter-based accessor properties).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/handlebars
Introduced in: 4.0.0Fixed in: 4.7.9
Fixnpm install handlebars@4.7.9

References