Skip to main content

CVE-2026-106444: CWE-116: Improper Encoding or Escaping of Output in handlebars-lang handlebars.js

0
Medium
VulnerabilityCVE-2026-106444cvecve-2026-106444cwe-116
Published: 10/06/2026 (10/06/2026, 19:01:14 UTC)
Source: CVE Database V5
Vendor/Project: handlebars-lang
Product: handlebars.js

Description

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.

CVSS v3.1

Score 4.7medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected software

handlebars-lang

handlebars.js

Affected versions
>=4.0.0 <4.7.10
handlebars
pkg:npm/handlebars

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 19:33:50 UTC

Technical Analysis

Handlebars.js versions from 4.0.0 up to but not including 4.7.10 contain a CWE-116 vulnerability due to improper escaping in Handlebars.precompile(). Specifically, the function uses quotedString() to emit static template text into generated JavaScript without escaping sequences that can terminate an enclosing HTML script element. If an application precompiles attacker-controlled template text and embeds the generated source directly inside an inline script element, an attacker can inject a closing script delimiter, causing subsequent attacker-controlled markup to be parsed and executed. Server-side rendering and precompiled templates served as external JavaScript files are not affected. The vulnerability is fixed in version 4.7.10.

Potential Impact

This vulnerability allows an attacker to inject script code by terminating an inline script element prematurely when attacker-controlled templates are precompiled and embedded inline. This can lead to cross-site scripting (XSS) with limited impact (confidentiality and integrity impact rated low, availability not affected). There are no known exploits in the wild.

Mitigation Recommendations

Upgrade handlebars.js to version 4.7.10 or later, where this issue is fixed. Avoid embedding precompiled templates generated from untrusted input directly inside inline script elements. Using server-side rendering or serving precompiled templates as external JavaScript files mitigates this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-06T16:49:40.590Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac549bb2cdf04f656d5e842

Added to database: 10/06/2026, 19:19:23 UTC

Last enriched: 10/06/2026, 19:33:50 UTC

Last updated: 10/06/2026, 20:19:15 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses