← Vulnerability feed

Vulnerability record · CVE-2021-23383 · published 4 May 2021

CVE-2021-23383: Handlebarsjs handlebars prototype pollution vulnerability

Handlebarsjs · Handlebars

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

9.8 CVSS 3.1 Critical EPSS 4.5% · top 8.8% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score, v2 7.5
4.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23383 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2026-33937Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…EPSS 1.7%9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%9.8CVE-2021-23369Handlebarsjs handlebars vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates comin…EPSS 7.0%9.8CVE-2021-20231Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.EPSS 3.8%8.8CVE-2022-21703Grafana cross-site request forgery vulnerabilityGrafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…EPSS 2.3%8.7CVE-2022-31097Grafana Unified Alerting stored XSS allows editor-to-admin privilege escalationGrafana 8.x and 9.x branches before 9.0.3, 8.5.9, 8.4.10 and 8.3.10 contain a stored cross-site scripting flaw in the Unified Alerting feature. An at…EPSS 69%analysed8.3CVE-2020-14664Oracle jdk vulnerabilityVulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to ex…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2021-23383), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.