CVE-2021-23383

CRITICAL9.8EPSS 5.7%

Prototype Pollution in handlebars

Published: 2/10/2022Modified: 4/28/2026

Description

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (11)