Vulnerability GHSA-xw65-4hp5-5hc7

Medium Risk
MEDIUM RISK
CVSS Score: 4.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 hours ago
October 08, 2026 at 05:52 PM UTC
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.0.0 - 4.7.9
4.0.0 - 4.7.9

Summary

Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates

Details

Summary

Handlebars.precompile() generates JavaScript source that is commonly embedded in browser <script> elements. Before the fix, static template text containing </script> was emitted unchanged. HTML parsers recognize </script> even inside a JavaScript string literal, closing the surrounding script element and allowing following attacker-controlled markup to be parsed and executed.

This affects applications that precompile attacker-controlled templates and embed the generated source directly in an HTML <script> element. It does not affect ordinary server-side rendering or precompiled templates delivered as external JavaScript files.

Details

Static text is serialized by quotedString() in lib/handlebars/compiler/code-gen.js. The generated JavaScript is valid, but JavaScript quoting alone does not make it safe to embed in HTML. In HTML script data, the sequence </script> terminates the element regardless of JavaScript string context.

On affected releases, this template:

safe</script><script>alert("XSS")</script><script>

could produce generated source containing:

return 'safe</script><script>alert("XSS")</script><script>';

When included inline in an HTML document, the first </script> closes the script containing the precompiled template. The next <script> element is then parsed as HTML and executes.

Proof of Concept

const Handlebars = require('handlebars');

const template = 'safe</script><script>alert("XSS")</script><script>';
const output = Handlebars.precompile(template);

console.log(output.includes('</script>'));

Affected versions print true. Embedding output directly in an inline <script> element allows the injected script tag to be parsed by the browser.

Workarounds

  • Do not inline precompiled output from untrusted templates into HTML documents.
  • Serve generated precompiled templates as external JavaScript files where practical.

Credits

Reported by Curly-Haired-Baboon Aka Laplas

Impacted packages

Timeline

Published
5 hours ago
October 08, 2026 at 05:52 PM UTC
Fixed (4.7.10)
Unknown
Unknown
Last Modified
5 hours ago
October 08, 2026 at 06:00 PM UTC