{"schema_version":1,"title":"Handlebars project Handlebars vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Handlebars project Handlebars: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Handlebars.js property access validation bypass in container.lookup, was published on 29 March 2026.","url":"https://junglewise.ai/threats/technologies/handlebars","json_url":"https://junglewise.ai/threats/technologies/handlebars.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/handlebars","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":13,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":2},"latest":[{"cvss":3.1,"slug":"handlebars-js-property-access-validation-bypass-in-container-lookup-25bcfec0","title":"Handlebars.js property access validation bypass in container.lookup","severity":"low","exploited":false,"published_at":"2026-03-29T15:16:37+00:00","url":"https://junglewise.ai/threats/handlebars-js-property-access-validation-bypass-in-container-lookup-25bcfec0"},{"cve":"CVE-2026-33916","cvss":3.1,"epss":0.0038,"slug":"cve-2026-33916-handlebars-js-prototype-pollution-in-resolvepartial-leads-to-xss","title":"Handlebars.js prototype pollution XSS via partial template injection","severity":"low","exploited":false,"published_at":"2026-03-26T22:20:51+00:00","url":"https://junglewise.ai/threats/cve-2026-33916-handlebars-js-prototype-pollution-in-resolvepartial-leads-to-xss"},{"cve":"CVE-2021-23383","cvss":3.1,"epss":0.0451,"slug":"cve-2021-23383-handlebars-prototype-pollution-in-template-compilation","title":"Handlebars prototype pollution in template compilation","severity":"low","exploited":false,"published_at":"2022-02-10T23:51:42+00:00","url":"https://junglewise.ai/threats/cve-2021-23383-handlebars-prototype-pollution-in-template-compilation"},{"cve":"CVE-2019-20922","cvss":3.1,"epss":0.0379,"slug":"cve-2019-20922-handlebars-regular-expression-denial-of-service","title":"Handlebars regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-02-10T20:38:22+00:00","url":"https://junglewise.ai/threats/cve-2019-20922-handlebars-regular-expression-denial-of-service"},{"cve":"CVE-2019-20920","cvss":3.1,"slug":"cve-2019-20920-handlebars-arbitrary-code-execution-in-lookup-helper","title":"Handlebars arbitrary code execution in lookup helper","severity":"low","exploited":false,"published_at":"2022-02-10T20:38:19+00:00","url":"https://junglewise.ai/threats/cve-2019-20920-handlebars-arbitrary-code-execution-in-lookup-helper"},{"slug":"handlebars-arbitrary-code-execution-via-lookup-helper-739dd450","title":"Handlebars arbitrary code execution via lookup helper","severity":"info","exploited":false,"published_at":"2020-09-04T15:07:38+00:00","url":"https://junglewise.ai/threats/handlebars-arbitrary-code-execution-via-lookup-helper-739dd450"},{"cvss":7.5,"slug":"handlebars-prototype-pollution-in-template-processing-676d30e6","title":"Handlebars prototype pollution in template processing","severity":"info","exploited":false,"published_at":"2020-09-04T15:06:32+00:00","url":"https://junglewise.ai/threats/handlebars-prototype-pollution-in-template-processing-676d30e6"},{"cvss":3.1,"slug":"handlebars-arbitrary-code-execution-in-lookup-helper-e5650e93","title":"Handlebars arbitrary code execution in lookup helper","severity":"low","exploited":false,"published_at":"2020-09-04T14:57:38+00:00","url":"https://junglewise.ai/threats/handlebars-arbitrary-code-execution-in-lookup-helper-e5650e93"},{"slug":"handlebars-denial-of-service-in-template-parser-7f538b11","title":"Handlebars Denial of Service in template parser","severity":"info","exploited":false,"published_at":"2020-09-03T23:20:12+00:00","url":"https://junglewise.ai/threats/handlebars-denial-of-service-in-template-parser-7f538b11"},{"cve":"CVE-2019-19919","cvss":3.1,"epss":0.0707,"slug":"cve-2019-19919-handlebars-prototype-pollution-remote-code-execution","title":"Handlebars prototype pollution remote code execution","severity":"low","exploited":false,"published_at":"2019-12-26T17:58:13+00:00","url":"https://junglewise.ai/threats/cve-2019-19919-handlebars-prototype-pollution-remote-code-execution"},{"cvss":3.1,"slug":"handlebars-prototype-pollution-remote-code-execution-cfff4bd0","title":"Handlebars prototype pollution remote code execution","severity":"low","exploited":false,"published_at":"2019-06-05T14:07:48+00:00","url":"https://junglewise.ai/threats/handlebars-prototype-pollution-remote-code-execution-cfff4bd0"},{"slug":"handlebars-moderate-severity-vulnerability-withdrawn-cad4e97e","title":"Handlebars moderate severity vulnerability (withdrawn)","severity":"info","exploited":false,"published_at":"2017-10-24T18:33:36+00:00","url":"https://junglewise.ai/threats/handlebars-moderate-severity-vulnerability-withdrawn-cad4e97e"},{"cve":"CVE-2015-8861","cvss":6.1,"epss":0.0261,"slug":"cve-2015-8861-handlebars-js-xss-in-unquoted-template-attributes","title":"Handlebars.js XSS in unquoted template attributes","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.72+00:00","url":"https://junglewise.ai/threats/cve-2015-8861-handlebars-js-xss-in-unquoted-template-attributes"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Handlebars project Handlebars","slug":"handlebars","vendor":{"name":"Handlebars project","slug":"handlebars-project","url":"https://junglewise.ai/threats/vendors/handlebars-project"},"aliases":[],"category":"library","homepage":"https://handlebarsjs.com/","repo_url":"https://github.com/handlebars-lang/handlebars.js","description":"Handlebars is a logic-less templating engine for JavaScript.","url":"https://junglewise.ai/threats/technologies/handlebars"},"most_severe":[{"cve":"CVE-2015-8861","cvss":6.1,"epss":0.0261,"slug":"cve-2015-8861-handlebars-js-xss-in-unquoted-template-attributes","title":"Handlebars.js XSS in unquoted template attributes","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.72+00:00","url":"https://junglewise.ai/threats/cve-2015-8861-handlebars-js-xss-in-unquoted-template-attributes"},{"cve":"CVE-2019-19919","cvss":3.1,"epss":0.0707,"slug":"cve-2019-19919-handlebars-prototype-pollution-remote-code-execution","title":"Handlebars prototype pollution remote code execution","severity":"low","exploited":false,"published_at":"2019-12-26T17:58:13+00:00","url":"https://junglewise.ai/threats/cve-2019-19919-handlebars-prototype-pollution-remote-code-execution"},{"cve":"CVE-2021-23383","cvss":3.1,"epss":0.0451,"slug":"cve-2021-23383-handlebars-prototype-pollution-in-template-compilation","title":"Handlebars prototype pollution in template compilation","severity":"low","exploited":false,"published_at":"2022-02-10T23:51:42+00:00","url":"https://junglewise.ai/threats/cve-2021-23383-handlebars-prototype-pollution-in-template-compilation"},{"cve":"CVE-2019-20922","cvss":3.1,"epss":0.0379,"slug":"cve-2019-20922-handlebars-regular-expression-denial-of-service","title":"Handlebars regular expression denial of service","severity":"low","exploited":false,"published_at":"2022-02-10T20:38:22+00:00","url":"https://junglewise.ai/threats/cve-2019-20922-handlebars-regular-expression-denial-of-service"},{"cve":"CVE-2026-33916","cvss":3.1,"epss":0.0038,"slug":"cve-2026-33916-handlebars-js-prototype-pollution-in-resolvepartial-leads-to-xss","title":"Handlebars.js prototype pollution XSS via partial template injection","severity":"low","exploited":false,"published_at":"2026-03-26T22:20:51+00:00","url":"https://junglewise.ai/threats/cve-2026-33916-handlebars-js-prototype-pollution-in-resolvepartial-leads-to-xss"},{"cvss":3.1,"slug":"handlebars-js-property-access-validation-bypass-in-container-lookup-25bcfec0","title":"Handlebars.js property access validation bypass in container.lookup","severity":"low","exploited":false,"published_at":"2026-03-29T15:16:37+00:00","url":"https://junglewise.ai/threats/handlebars-js-property-access-validation-bypass-in-container-lookup-25bcfec0"},{"cve":"CVE-2019-20920","cvss":3.1,"slug":"cve-2019-20920-handlebars-arbitrary-code-execution-in-lookup-helper","title":"Handlebars arbitrary code execution in lookup helper","severity":"low","exploited":false,"published_at":"2022-02-10T20:38:19+00:00","url":"https://junglewise.ai/threats/cve-2019-20920-handlebars-arbitrary-code-execution-in-lookup-helper"},{"cvss":3.1,"slug":"handlebars-arbitrary-code-execution-in-lookup-helper-e5650e93","title":"Handlebars arbitrary code execution in lookup helper","severity":"low","exploited":false,"published_at":"2020-09-04T14:57:38+00:00","url":"https://junglewise.ai/threats/handlebars-arbitrary-code-execution-in-lookup-helper-e5650e93"},{"cvss":3.1,"slug":"handlebars-prototype-pollution-remote-code-execution-cfff4bd0","title":"Handlebars prototype pollution remote code execution","severity":"low","exploited":false,"published_at":"2019-06-05T14:07:48+00:00","url":"https://junglewise.ai/threats/handlebars-prototype-pollution-remote-code-execution-cfff4bd0"},{"cvss":7.5,"slug":"handlebars-prototype-pollution-in-template-processing-676d30e6","title":"Handlebars prototype pollution in template processing","severity":"info","exploited":false,"published_at":"2020-09-04T15:06:32+00:00","url":"https://junglewise.ai/threats/handlebars-prototype-pollution-in-template-processing-676d30e6"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}