CVE-2026-106444
Last modified
CVE-2026-106444 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element.
Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106444?
How severe is CVE-2026-106444?
How do I fix CVE-2026-106444?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-106439Hydra is a framework for elegantly configuring complex appli…8.5
- CVE-2026-10644The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mch…3.1
- CVE-2026-106440Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106441Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106442Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106443WeasyPrint helps web developers to create PDF documents. Pri…8.8
- CVE-2026-106445Handlebars provides the power necessary to let users build s…9.2
- CVE-2026-106446Handlebars provides the power necessary to let users build s…9.8
- CVE-2026-106447StableLib is a stable library of useful TypeScript and JavaS…8.7
- CVE-2026-106448StableLib is a stable library of useful TypeScript and JavaS…8.9
- CVE-2026-106449yawkat LZ4 Java provides LZ4 compression for Java. Prior to …3.7
- CVE-2026-10645The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted t…5.5
Are you affected by CVE-2026-106444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
