Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 npm

Cross-Site Scripting in handlebars

GHSA-9prh-257w-9277 · CVE-2015-8861

Published · Modified

Description

Versions of handlebars prior to 4.0.0 are affected by a cross-site scripting vulnerability when attributes in handlebar templates are not quoted.

Proof of Concept

Template:
<a href={{foo}}/>

Input:
{ 'foo' : 'test.com onload=alert(1)'}

Rendered result:
<a href=test.com onload=alert(1)/>

Recommendation

Update to version 4.0.0 or later.
Alternatively, ensure that all attributes in handlebars templates are encapsulated with quotes.

Ready to move

Start Securing

Free, no credit card | First findings in minutes