MEDIUM6.1
GHSA-9prh-257w-9277
Cross-Site Scripting in handlebars
Quick fix
GHSA-9prh-257w-9277 — handlebars: upgrade to the fixed version with the command below.
npm install handlebars@4.0.0Details
Versions of `handlebars` prior to 4.0.0 are affected by a cross-site scripting vulnerability when attributes in handlebar templates are not quoted.
## Proof of Concept Template: ```<a href={{foo}}/>```
Input: ```{ 'foo' : 'test.com onload=alert(1)'}```
Rendered result: ```<a href=test.com onload=alert(1)/>```
## Recommendation
Update to version 4.0.0 or later. Alternatively, ensure that all attributes in handlebars templates are encapsulated with quotes.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8861[ADVISORY]
- https://github.com/wycats/handlebars.js/pull/1083[WEB]
- https://blog.srcclr.com/handlebars_vulnerability_research_findings[WEB]
- https://github.com/advisories/GHSA-9prh-257w-9277[ADVISORY]
- https://github.com/wycats/handlebars.js[PACKAGE]
- https://www.npmjs.com/advisories/61[WEB]
- https://www.sourceclear.com/blog/handlebars_vulnerability_research_findings[WEB]
- https://www.tenable.com/security/tns-2016-18[WEB]
- http://www.openwall.com/lists/oss-security/2016/04/20/11[WEB]
- http://www.securityfocus.com/bid/96434[WEB]