Lucene search

K
osvGoogleOSV:GHSA-W457-6Q6X-CGP9
HistoryDec 26, 2019 - 5:58 p.m.

Prototype Pollution in handlebars

2019-12-2617:58:13
Google
osv.dev
22

0.009 Low

EPSS

Percentile

83.0%

Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects’ __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Recommendation

Upgrade to version 3.0.8, 4.3.0 or later.