Executive brief
Handlebars, a popular template engine for Node.js, is vulnerable to cross-site scripting (XSS). This occurs when templates use HTML attributes that are not enclosed in quotes, allowing an attacker to inject malicious scripts. If exploited, this could allow an attacker to steal user session data or perform unauthorized actions on behalf of users viewing the affected web pages.
Technical details
A cross-site scripting (XSS) vulnerability exists in Handlebars.js before version 4.0.0 due to improper escaping of unquoted attributes in templates. The root cause is located in 'lib/handlebars/utils.js', where the library fails to sufficiently neutralize input when a template attribute is not wrapped in quotes. A remote attacker can exploit this by providing malicious input that is rendered into an unquoted attribute, leading to the execution of arbitrary JavaScript in the context of the victim's browser. This is a network-based attack that typically requires user interaction (viewing the rendered page). The issue is resolved in Handlebars version 4.0.0.
Affected products
- Handlebars project handlebars.js < 4.0.0
Timeline
- 2015-08-12: patched: Handlebars 4.0.0 released addressing the issue
- 2016-04-20: disclosed: Public disclosure via oss-security mailing list
- 2017-01-23: advisory: NVD published CVE-2015-8861