Junglewise Threat Intelligence

CVE-2026-55760: jknack handlebars.java path traversal in FileTemplateLoader

CVE-2026-55760 · Severity: high · CVSS 7.5 · Published 2026-07-08

Vendors: Maven.

Executive brief

Handlebars.java is a popular Java library used to generate dynamic web content and documents using templates. A security flaw in how the library handles file paths allows an attacker to bypass directory restrictions and read sensitive files from the server's file system. This could lead to the exposure of configuration files, source code, or other private data if the application uses user-provided input to select which template to load.

Technical details

A path traversal vulnerability exists in Handlebars.java prior to version 4.5.2. The issue resides in the FileTemplateLoader and ClassPathTemplateLoader components, which fail to properly sanitize template names. If an application passes unsanitized user input (such as URL or request parameters) to the Handlebars.compile() method, a remote attacker can use directory traversal sequences (e.g., ../) to escape the intended template directory. This allows for unauthorized reading of arbitrary files on the host system that the Java process has permission to access. The vulnerability is addressed in version 4.5.2 by improving path normalization and validation.

Affected products

  • jknack handlebars.java < 4.5.2

Timeline

  • 2026-06-15: patched: Fix committed to repository
  • 2026-06-16: advisory: GitHub Security Advisory published
  • 2026-07-08: disclosed: CVE published to NVD

References