CVE-2026-106444: Handlebars-Lang Handlebars.js

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.

Affected products

Published 2026-10-06. Last modified 2026-10-07.