CVE-2026-106444: CWE-116: Improper Encoding or Escaping of Output in handlebars-lang handlebars.js
Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
CVSS v3.1
Score 4.7medium
Affected software
handlebars-lang
handlebars.js
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Handlebars.js versions from 4.0.0 up to but not including 4.7.10 contain a CWE-116 vulnerability due to improper escaping in Handlebars.precompile(). Specifically, the function uses quotedString() to emit static template text into generated JavaScript without escaping sequences that can terminate an enclosing HTML script element. If an application precompiles attacker-controlled template text and embeds the generated source directly inside an inline script element, an attacker can inject a closing script delimiter, causing subsequent attacker-controlled markup to be parsed and executed. Server-side rendering and precompiled templates served as external JavaScript files are not affected. The vulnerability is fixed in version 4.7.10.
Potential Impact
This vulnerability allows an attacker to inject script code by terminating an inline script element prematurely when attacker-controlled templates are precompiled and embedded inline. This can lead to cross-site scripting (XSS) with limited impact (confidentiality and integrity impact rated low, availability not affected). There are no known exploits in the wild.
Mitigation Recommendations
Upgrade handlebars.js to version 4.7.10 or later, where this issue is fixed. Avoid embedding precompiled templates generated from untrusted input directly inside inline script elements. Using server-side rendering or serving precompiled templates as external JavaScript files mitigates this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-06T16:49:40.590Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac549bb2cdf04f656d5e842
Added to database: 10/06/2026, 19:19:23 UTC
Last enriched: 10/06/2026, 19:33:50 UTC
Last updated: 10/06/2026, 20:19:15 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.