TWO critical remote code execution flaws have been disclosed in Handlebars[.]js, with public PoC code available. The vulnerabilities affect Handlebars 4.0.0 through 4.7.9 and are fixed in 4.7.10. CVE-2026-106445 (CWE-94) carries a 9.2 CVSSv3 score and enables JavaScript injection via an own property check bypass, by bypassing the library’s deny list to access the Function constructor when allowProtoMethodsByDefault is enabled on untrusted templates.
CVE-2026-106446, rated 9.8, is an AST type confusion affecting compile() and precompile() that allows unvalidated values to be written into generated code; an untrusted object can carry arbitrary JavaScript, with a common trigger being a field from a JSON request body passed to compile(). Although both flaws are now public with proofs-of-concept, the advisories indicate no confirmed exploitation in the wild to date.
The evidence points to a broad impact: Handlebars[.]js is widely used, with the project citing over 172 million monthly downloads. The two GitHub advisories—GHSA-p8wg-vrv2-v86f and GHSA-8r5x-fm3f-whwj—document the issues in full. Practical response centres on upgrading to Handlebars 4.7.10 as the durable fix.
If immediate update isn’t possible, apply mitigations: never set allowProtoMethodsByDefault to true for untrusted templates, ensure that values passed to compile() are strings (not objects), and consider a runtime-only build on servers where templates are pre-compiled at build time. There is no reported exploitation in the wild, but patching remains urgent given the public PoC and broad deployment.