VDB
Sign up
CRITICAL9.8

GHSA-w457-6q6x-cgp9

Prototype Pollution in handlebars

Quick fix

GHSA-w457-6q6x-cgp9 — handlebars: upgrade to the fixed version with the command below.

npm install handlebars@4.3.0

Details

Versions of `handlebars` prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' `__proto__` and `__defineGetter__` properties, which may allow an attacker to execute arbitrary code through crafted payloads.

## Recommendation

Upgrade to version 3.0.8, 4.3.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/handlebars
Introduced in: 4.0.0Fixed in: 4.3.0
Fixnpm install handlebars@4.3.0
RubyGems/bootstrap-wysihtml5-rails
Introduced in: 0.3.3.5

No fixed version published yet for bootstrap-wysihtml5-rails (bundler). Pin to a known-safe version or switch to an alternative.

npm/handlebars
Introduced in: 0Fixed in: 3.0.8
Fixnpm install handlebars@3.0.8

References