GHSA-3cqr-58rm-57f8
Dashboard / Vulnerabilities / GHSA-3cqr-58rm-57f8
GHSA-3cqr-58rm-57f8
Summary: Arbitrary Code Execution in Handlebars
Details: Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
References: https://nvd.nist.gov/vuln/detail/CVE-2019-20920, https://github.com/handlebars-lang/handlebars.js/commit/156061eb7707575293613d7fdf90e2bdaac029ee, https://github.com/handlebars-lang/handlebars.js/commit/d54137810a49939fd2ad01a91a34e182ece4528e, https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478, https://www.npmjs.com/advisories/1316, https://www.npmjs.com/advisories/1324, https://www.npmjs.com/package/handlebars
Affected packages
Package
Name: handlebars
Purl: pkg:npm/handlebars
Affected ranges
Type: SEMVER
Events:
