CVE-2026-33941
handlebars-lang handlebars.js, Cluster Observability Operator 1.5.0, Red Hat OpenShift Dev Spaces 3.27
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validat...
- CVSS
- 8.2
- EPSS
- 0.29% 21.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.28