
Key points
- CVE-2026-106446 affects Handlebars versions 4.0.0 through 4.7.9.
- The flaw bypasses AST validation added in version 4.7.9 by exploiting unchecked node types.
- Applications passing untrusted objects to compile() or precompile() are at risk.
A critical remote code execution (RCE) vulnerability in the popular JavaScript template engine Handlebars has been addressed in version 4.7.10. The flaw, tracked as CVE-2026-106446, allows attackers to execute arbitrary code on servers or in client environments by bypassing security checks introduced in the previous release.
Handlebars 4.7.9 added validation for Abstract Syntax Trees (ASTs) to mitigate earlier vulnerabilities. However, this validator only inspected values on `PathExpression`, `NumberLiteral`, and `BooleanLiteral` nodes. It ignored plain objects without a `type` field, as well as strings and other non-object values. The compiler subsequently wrote these unchecked values directly into the generated JavaScript code, creating an injection vector.
How the bypass works
According to the GitHub advisory GHSA-8r5x-fm3f-whwj, the vulnerability exists because the validator runs in `parseWithoutProcessing()` and walks the entire AST but skips specific node types. For instance, a `Program` node with `blockParams` containing a JavaScript expression passes validation because the object lacks a `type` field.
The advisory details several ways attackers can inject raw JavaScript. With default options, manipulating `Program.blockParams.length` writes code into the container program. If the `stringParams` option is enabled, attackers can exploit `depth` values on non-`PathExpression` parameters, or inject raw literals via `StringLiteral.value` and `PathExpression.original`.
Who is affected
Applications that only pass template strings to Handlebars are not affected by this vulnerability. The risk arises when applications pass untrusted objects to `Handlebars.compile()` or `Handlebars.precompile()`. This scenario often occurs when developers accept parsed JSON request bodies as template inputs.
When using `compile()`, the malicious code executes on the server during template rendering. With `precompile()`, the injected code is embedded in the output and runs wherever that output is loaded, potentially affecting client-side security. This flaw bypasses protections added for GHSA-2w6w-674q-4c4q, GHSA-xhpv-hc6g-r9c6, and GHSA-3mfm-83xf-c92r.
What happens next
Security teams should update Handlebars to version 4.7.10 immediately if they use versions between 4.0.0 and 4.7.9. Developers should audit their codebases to ensure that untrusted data, such as JSON from API requests, is never passed directly to compilation functions. If updating is not immediately possible, restricting input to template strings only provides a temporary mitigation.
What to do and how to stay safe: Handlebars
- Automated tools find known code defects but miss logical errors in how systems interact.
- False positives waste time if you do not verify findings against your actual environment.
- Outsourcing the scan is affordable, but you must retain control of the remediation process.
Automated scanning finds known flaws but misses logic errors and configuration mistakes. Combine weekly scans with manual reviews and periodic penetration tests for a complete defence.
Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits
General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Does this vulnerability affect all Handlebars users?
No, applications that only pass template strings to Handlebars are not affected; only those passing untrusted objects are at risk.
Which versions of Handlebars are vulnerable?
Versions 4.0.0 through 4.7.9 are vulnerable; version 4.7.10 contains the fix.
What is the severity of CVE-2026-106446?
The vulnerability is rated as critical severity according to the GitHub advisory.



