VDB
Sign up
CRITICAL9.8

GHSA-f2jv-r9rf-7988

Remote code execution in handlebars when compiling templates

Quick fix

GHSA-f2jv-r9rf-7988 — handlebars: upgrade to the fixed version with the command below.

npm install handlebars@4.7.7

Details

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/handlebars
Introduced in: 0Fixed in: 4.7.7
Fixnpm install handlebars@4.7.7
Maven/org.webjars:handlebars
Introduced in: 0Fixed in: 4.7.7
Fix# pom.xml: bump <version>4.7.7</version> for org.webjars:handlebars
Maven/org.webjars.npm:handlebars
Introduced in: 0Fixed in: 4.7.7
Fix# pom.xml: bump <version>4.7.7</version> for org.webjars.npm:handlebars
Maven/org.webjars.bowergithub.wycats:handlebars.js
Introduced in: 0Fixed in: 4.7.7
Fix# pom.xml: bump <version>4.7.7</version> for org.webjars.bowergithub.wycats:handlebars.js

References