Launch Week Day 1: Announcing Security Design Review
HIGH 7.3 npm

Prototype Pollution in handlebars

GHSA-q42p-pg8m-cqh6

Published ยท Modified

Description

Versions of handlebars prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects' prototype, thus allowing an attacker to execute arbitrary code on the server.

Recommendation

For handlebars 4.1.x upgrade to 4.1.2 or later.
For handlebars 4.0.x upgrade to 4.0.14 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes