HIGH7.3
GHSA-q42p-pg8m-cqh6
Prototype Pollution in handlebars
Quick fix
GHSA-q42p-pg8m-cqh6 — handlebars: upgrade to the fixed version with the command below.
npm install handlebars@4.1.2Details
Versions of `handlebars` prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects' prototype, thus allowing an attacker to execute arbitrary code on the server.
## Recommendation
For handlebars 4.1.x upgrade to 4.1.2 or later. For handlebars 4.0.x upgrade to 4.0.14 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/handlebars-lang/handlebars.js/issues/1495[WEB]
- https://github.com/handlebars-lang/handlebars.js/commit/0d6d8c335ad81bad1b672fc56b6a44f6aa472dac[WEB]
- https://github.com/handlebars-lang/handlebars.js/commit/7372d4e9dffc9d70c09671aa28b9392a1577fd86[WEB]
- https://github.com/handlebars-lang/handlebars.js/commit/85c8783b34fc6d36145d8b53885ad0b9e3c3f9c4[WEB]
- https://github.com/handlebars-lang/handlebars.js/commit/cd38583216dce3252831916323202749431c773e[WEB]
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-173692[WEB]
- https://www.npmjs.com/advisories/755[WEB]