CVE-2026-55760: Jknack Handlebars.java

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL path parameters, request parameters, or other user-controlled sources. This issue is fixed in version 4.5.2.

Affected products

  • Jknack Handlebars.java: before 4.5.2 (fixed in 4.5.2)

Published 2026-07-08. Last modified 2026-07-10.