Executive brief
Handlebars.js is a widely-used template engine for rendering dynamic content in web applications. A flaw in how it resolves partial templates allows an attacker to inject arbitrary HTML/JavaScript into rendered pages when the application is vulnerable to prototype pollution. An attacker can pollute JavaScript's Object.prototype and cause Handlebars to use a malicious string as a template partial, leading to cross-site scripting (XSS) attacks that steal user data or perform actions on their behalf.
Technical details
The vulnerability exists in lib/handlebars/runtime.js within resolvePartial() and invokePartial() functions. The code performs unguarded bracket-access property lookup (partial = options.partials[options.name]) that traverses the prototype chain without checking hasOwnProperty(). When Object.prototype has been seeded with a key matching a partial reference in a template (e.g., "widget"), the lookup succeeds and returns the polluted string value. Critically, this polluted content is rendered without HTML escaping, resulting in unescaped XSS. The attack requires two preconditions: (1) the target application must be vulnerable to prototype pollution via a separate vector such as qs, minimist, or JSON merge operations, and (2) the attacker must know or guess a partial name referenced in the template. Although the runtime prints a prototype access warning, the partial is still resolved and rendered, contradicting the documented security model. A patch is available in version 4.7.9.
Affected products
- handlebars-lang handlebars 4.0.0 to 4.7.8
Timeline
- 2026-03-26: disclosed: GitHub Security Advisory GHSA-2qvq-rjwj-gvw9 published
- 2026-03-26: patched: Version 4.7.9 released with security fixes
References
- https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2qvq-rjwj-gvw9
- https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
- https://github.com/handlebars-lang/handlebars.js
- https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9