VDB
Sign up
MEDIUM6.1

GHSA-9prh-257w-9277

Cross-Site Scripting in handlebars

Quick fix

GHSA-9prh-257w-9277 — handlebars: upgrade to the fixed version with the command below.

npm install handlebars@4.0.0

Details

Versions of `handlebars` prior to 4.0.0 are affected by a cross-site scripting vulnerability when attributes in handlebar templates are not quoted.

## Proof of Concept Template: ```<a href={{foo}}/>```

Input: ```{ 'foo' : 'test.com onload=alert(1)'}```

Rendered result: ```<a href=test.com onload=alert(1)/>```

## Recommendation

Update to version 4.0.0 or later. Alternatively, ensure that all attributes in handlebars templates are encapsulated with quotes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/handlebars
Introduced in: 0Fixed in: 4.0.0
Fixnpm install handlebars@4.0.0

References