CVE-2026-33941
handlebars-lang handlebars.js, Cluster Observability Operator 1.5.0, Red Hat OpenShift Dev Spaces 3.27 취약점
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validat...
- 대응 우선순위
- 점검
- CVSS
- 8.2
- EPSS
- 0.29% 백분위 21.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.03.28