CVE-2019-19919: Handlebars.js Project Handlebars.js
Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Affected products
- Handlebars.js Project Handlebars.js: version 1.0.6 only; version 1.0.7 only; version 1.0.8 only; version 1.0.9 only; version 1.0.10 only; version 1.0.11 only; …
- Tenable Tenable.sc: before 5.19.0 (fixed in 5.19.0)
Published 2019-12-20. Last modified 2026-06-17.