Vulnerability GHSA-xw65-4hp5-5hc7
Summary
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
Details
Summary
Handlebars.precompile() generates JavaScript source that is commonly embedded in browser <script> elements. Before the fix, static template text containing </script> was emitted unchanged. HTML parsers recognize </script> even inside a JavaScript string literal, closing the surrounding script element and allowing following attacker-controlled markup to be parsed and executed.
This affects applications that precompile attacker-controlled templates and embed the generated source directly in an HTML <script> element. It does not affect ordinary server-side rendering or precompiled templates delivered as external JavaScript files.
Details
Static text is serialized by quotedString() in lib/handlebars/compiler/code-gen.js. The generated JavaScript is valid, but JavaScript quoting alone does not make it safe to embed in HTML. In HTML script data, the sequence </script> terminates the element regardless of JavaScript string context.
On affected releases, this template:
safe</script><script>alert("XSS")</script><script>
could produce generated source containing:
return 'safe</script><script>alert("XSS")</script><script>';
When included inline in an HTML document, the first </script> closes the script containing the precompiled template. The next <script> element is then parsed as HTML and executes.
Proof of Concept
const Handlebars = require('handlebars');
const template = 'safe</script><script>alert("XSS")</script><script>';
const output = Handlebars.precompile(template);
console.log(output.includes('</script>'));
Affected versions print true. Embedding output directly in an inline <script> element allows the injected script tag to be parsed by the browser.
Workarounds
- Do not inline precompiled output from untrusted templates into HTML documents.
- Serve generated precompiled templates as external JavaScript files where practical.
Credits
Reported by Curly-Haired-Baboon Aka Laplas
Related Vulnerabilities
Other vulnerabilities affecting the same packages