← Vulnerability feed

Vulnerability record · CVE-2019-20920 · published 30 September 2020

CVE-2019-20920: Handlebarsjs handlebars code injection vulnerability

Handlebarsjs · Handlebars

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

8.1 CVSS 3.1 High EPSS 3.2% · top 12.4% CWE-94 · Code injection
8.1CVSS 3.1 base score, v2 6.8
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33937Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…EPSS 1.7%9.8CVE-2021-23383Handlebarsjs handlebars prototype pollution vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from a…EPSS 4.5%9.8CVE-2021-23369Handlebarsjs handlebars vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates comin…EPSS 7.0%8.2CVE-2026-33941Handlebarsjs handlebars cross-site scripting vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…EPSS 0.22%8.1CVE-2026-33940Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa…EPSS 0.79%8.1CVE-2026-33938Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable…EPSS 0.84%7.5CVE-2026-33939Handlebarsjs handlebars vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains d…EPSS 0.76%7.5CVE-2019-20922Handlebarsjs handlebars uncontrolled resource consumption vulnerabilityHandlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop …EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2019-20920), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.