← Vulnerability feed

Vulnerability record · CVE-2019-19919 · published 20 December 2019

CVE-2019-19919: Handlebars.js project handlebars.js prototype pollution vulnerability

HHandlebars.Js Project · Handlebars.Js

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

9.8 CVSS 3.1 Critical EPSS 7.1% · top 6.0% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score, v2 7.5
7.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.npmjs.com/advisories/1164 Third Party Advisory
https://www.tenable.com/security/tns-2021-14 PatchThird Party Advisory
https://www.npmjs.com/advisories/1164 Third Party Advisory
https://www.tenable.com/security/tns-2021-14 PatchThird Party Advisory

Track CVE-2019-19919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed9.8CVE-2021-44790Apache HTTP Server mod_lua multipart parser buffer overflowA crafted request body triggers an out-of-bounds write in the mod_lua multipart parser when r:parsebody() is called from Lua scripts. The flaw affect…EPSS 97%analysed9.8CVE-2021-41116Getcomposer composer command injection vulnerabilityComposer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependen…EPSS 2.9%9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%9.8CVE-2019-19646Sqlite vulnerabilitypragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.EPSS 5.4%9.1CVE-2020-7061Php out-of-bounds read vulnerabilityIn PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR fi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2019-19919), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.