Handlebars RCE flaw allows server compromise via prototype bypass
A critical vulnerability in the Handlebars templating engine enables remote code execution by bypassing security controls, affecting versions up to 4.7.9.

Key points
- CVE-2026-106445 allows arbitrary JavaScript execution on servers using vulnerable Handlebars versions.
- The flaw exploits how the library handles own properties on prototype objects, bypassing deny lists.
- Version 4.7.10 patches the issue; users of versions 4.0.0 through 4.7.9 are at risk.
Organisations using the Handlebars JavaScript templating engine face a critical remote code execution risk. A newly disclosed vulnerability, CVE-2026-106445, allows attackers to execute arbitrary code on servers if they can control the input to a template rendered with specific configuration settings. The flaw stems from an internal logic error that permits access to dangerous constructor functions despite existing security filters.
How it unfolded
- The Handlebars library includes a prototype-access deny list designed to block access to sensitive methods like `constructor`.
- An analysis of the `lookupProperty` function revealed it trusts "own properties" of an object without further validation.
- Attackers discovered that prototype objects, such as `Function.prototype`, contain `constructor` as an own property.
- When a template resolves to a prototype object, the library returns the `constructor` value before checking the deny list, effectively nullifying the security control.
- This bypass allows an attacker to obtain the `Function` constructor and execute arbitrary JavaScript code on the server.
Who is affected
Any application using Handlebars versions 4.0.0 through 4.7.9 is vulnerable to this exploit. The attack vector requires the ability to render a controlled template. Crucially, the configuration option `allowProtoMethodsByDefault` must be set to true for the exploit to succeed. This setting permits access to prototype methods, which is a prerequisite for reaching the `Function.prototype` object where the bypass occurs. Applications that do not enable this setting or that use stricter sandboxing may be less susceptible, but the underlying logic flaw remains present in the codebase.
The fix
A patch has been released in version 4.7.10 of the Handlebars npm package. Security teams should update their dependencies immediately. The fix addresses the logic error in `lookupProperty` to ensure that even own properties on prototype objects are subjected to the same security checks as prototype-derived values. Until the update is applied, administrators should review their Handlebars configuration and consider disabling `allowProtoMethodsByDefault` if business logic permits, although this may break existing functionality.
Background: Sandboxing
Sandboxing fails when analysts rely on automated tools without manual verification. Common errors include ignoring timing mechanisms, skipping network simulation, and neglecting memory-only threats. Fix these by combining dynamic execution with manual inspection and multi-stage detonation.
Read the full guide: Sandboxing Mistakes: How to Avoid Detection Evasion
What to do and how to stay safe: Handlebars
- Testing patches in isolation prevents configuration drift and system instability.
- Automation reduces human error but requires strict change control policies.
- Backported fixes offer security benefits without the overhead of major version upgrades.
Patch management balances security with stability, requiring careful testing and prioritisation. Implement automated scanning for dependencies and isolate legacy systems that cannot be updated.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS severity of CVE-2026-106445?
The vulnerability is rated as critical severity according to the GitHub advisory GHSA-p8wg-vrv2-v86f.
Which versions of Handlebars are vulnerable?
Versions greater than or equal to 4.0.0 and less than or equal to 4.7.9 are affected.
Is there a patch available for this vulnerability?
Yes, version 4.7.10 patches the vulnerability and is available via npm.



