← Vulnerability feed

Vulnerability record · CVE-2026-33916 · published 27 March 2026

CVE-2026-33916: Handlebarsjs handlebars cross-site scripting vulnerability

Handlebarsjs · Handlebars

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates and reduces the attack surface.

4.7 CVSS 3.1 Medium EPSS 0.38% · top 70.3% CWE-79 · Cross-site scriptingCWE-1321 · Prototype pollution
4.7CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates and reduces the attack surface.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33916 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33937Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…EPSS 1.7%9.8CVE-2021-23383Handlebarsjs handlebars prototype pollution vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from a…EPSS 4.5%9.8CVE-2021-23369Handlebarsjs handlebars vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates comin…EPSS 7.0%8.2CVE-2026-33941Handlebarsjs handlebars cross-site scripting vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…EPSS 0.22%8.1CVE-2026-33940Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa…EPSS 0.79%8.1CVE-2026-33938Handlebarsjs handlebars code injection vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable…EPSS 0.84%8.1CVE-2019-20920Handlebarsjs handlebars code injection vulnerabilityHandlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allow…EPSS 3.2%7.5CVE-2026-33939Handlebarsjs handlebars vulnerabilityHandlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains d…EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2026-33916), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.