External risk intelligence

Handlebars Code Execution Vulnerability via AST Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-106446

Handlebars is a templating library used within applications. While it is frequently used in internet-facing web applications to render dynamic content, the vulnerability requires the application to accept and compile untrusted user-supplied objects instead of standard template strings. Its reachability depends entirely on specific, non-standard implementation patterns within the host application.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A recent vulnerability has been identified in Handlebars, a templating technology. This issue could allow an attacker to execute code on the server if specific, non-standard configurations are in place where user-supplied objects are compiled instead of template strings. The main concern is confirming whether your applications utilize Handlebars in this specific, susceptible manner.

  • Code execution risk in Handlebars.
  • Check for non-standard object compilation.
  • Confirm relevance and exposure to risks.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by supplying a specially crafted object to the Handlebars.compile() or Handlebars.precompile() functions, bypassing security checks designed to validate template inputs. This bypass allows the attacker to embed JavaScript expressions within the object's properties, which the Handlebars compiler then includes in the generated JavaScript code. When this compiled code is rendered or loaded, it can lead to the execution of arbitrary JavaScript within the server process.

  • Attacker must supply an object, not a template string.
  • Bypasses AST validation to embed JavaScript expressions.
  • Leads to code execution in the server process.

Live Threat

Current exploitation, exposure, and threat context

When an application accepts pre-parsed Abstract Syntax Tree (AST) objects instead of template strings, an attacker could supply specially crafted JavaScript expressions. This could lead to code execution within the server process if the compiled output is rendered or loaded. Applications that only accept template strings are not affected.

  • Server process and application logic.
  • Attacker supplies malicious AST objects.
  • Uncontrolled code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners are responsible for addressing this vulnerability, as it impacts the Handlebars templating library used within their applications. The first step is to identify all instances of Handlebars, confirm if they are processing user-supplied AST objects instead of template strings, and assess business criticality to prioritize remediation efforts.

  • Application owners must address this.
  • Verify if AST objects are processed.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Handlebars and how is it used?

Handlebars is a widely used JavaScript templating library. Developers integrate it into web applications to transform data into dynamic HTML by building semantic templates. It separates the presentation logic from the underlying data, making it easier to render content consistently across server-side and client-side environments.

What does CWE-94 and CWE-843 mean for CVE-2026-106446?

These weaknesses refer to Improper Control of Generation of Code (CWE-94) and Access of Resource Using Incompatible Type (CWE-843). In this context, it means the compiler fails to properly validate the structure of pre-parsed objects, allowing an attacker to inject arbitrary JavaScript expressions that the library mistakenly treats as trusted template logic.

How does an attacker trigger this vulnerability?

An attacker must supply a specially crafted object—rather than a standard template string—directly to the compile or precompile functions. If your application only passes standard strings to Handlebars, it is not affected. The vulnerability relies on the application incorrectly accepting and processing untrusted, complex objects as if they were valid template structures.

Do I need to worry if my app uses Handlebars?

Halo Surface Signal indicates that while Handlebars is common, this risk is conditional. It depends on whether your code architecture uses non-standard patterns that ingest user-provided objects for compilation. If your implementation only processes raw template strings, you are likely not susceptible to this specific execution path.

What are the first steps to secure my application?

Begin by auditing your codebase to identify any locations where Handlebars.compile() or precompile() are used with objects rather than strings. If you find such patterns, prioritize updating the library to version 4.7.10 or later, which implements the necessary validation to block malicious AST structures.

References