CVE-2026-33916: Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Published Mar 26, 2026
·
Updated

Summary

resolvePartial() in the Handlebars runtime resolves partial names via a plain property lookup on options.partials without guarding against prototype-chain traversal. When Object.prototype has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS.

Description

The root cause is in lib/handlebars/runtime.js inside resolvePartial() and invokePartial():

javascript // Vulnerable: plain bracket access traverses Object.prototype partial = options.partials[options.name];

hasOwnProperty is never checked, so if Object.prototype has been seeded with a key whose name matches a partial reference in the template (e.g. widget), the lookup succeeds and the polluted string is returned. The runtime emits a prototype-access warning, but the partial is still resolved and its content is inserted into the rendered output unescaped. This contradicts the documented security model and is distinct from CVE-2021-23369 and CVE-2021-23383, which addressed data property access rather than partial template resolution.

Prerequisites for exploitation: 1. The target application must be vulnerable to prototype pollution (e.g. via qs, minimist, or any querystring/JSON merge sink). 2. The attacker must know or guess the name of a partial reference used in a template.

Proof of Concept

javascript const Handlebars = require('handlebars');

// Step 1: Prototype pollution (via qs, minimist, or another vector) Object.prototype.widget = '<img src=x onerror="alert(document.domain)">';

// Step 2: Normal template that references a partial const template = Handlebars.compile('<div>Welcome! {{> widget}}</div>');

// Step 3: Render — XSS payload injected unescaped const output = template({}); // Output: <div>Welcome! <img src=x onerror="alert(document.domain)"></div>

> The runtime prints a prototype access warning claiming "access has been denied," but the partial still resolves and returns the polluted value.

Workarounds

- Apply Object.freeze(Object.prototype) early in application startup to prevent prototype pollution. Note: this may break other libraries. - Use the Handlebars runtime-only build (handlebars/runtime), which does not compile templates and reduces the attack surface.

Other sources

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, resolvePartial() in the Handlebars runtime resolves partial names via a plain property lookup on options.partials without guarding against prototype-chain traversal. When Object.prototype has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply Object.freeze(Object.prototype) early in application startup to prevent prototype pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (handlebars/runtime), which does not compile templates and reduces the attack surface.

MITRE

Affected Software

3 affected componentsFixes available
npm/handlebars>=4.0.0<4.7.9
4.7.9
Handlebarsjs Handlebars Node.js>=4.0.0<4.7.9
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data<=v4.8 v5.0v5.1v5.2v5.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/handlebars to a version that resolves this vulnerability.

    Fixed in 4.7.9
  2. Configuration

    Call Object.freeze(Object.prototype) early in application startup to prevent prototype pollution.

    JavaScript Object.prototype Object.freeze(Object.prototype) = applied
  3. Configuration

    Use the Handlebars runtime-only build (handlebars/runtime), which does not compile templates and reduces the attack surface. This may break other libraries.

    handlebars build = runtime-only (handlebars/runtime)

Event History

Mar 26, 2026
Advisory Published
via GitHub·10:20 PM
Data Sourced
via GitHub·10:20 PM
DescriptionSeverityWeaknessAffected Software
Mar 27, 2026
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyAffected Software
Jun 19, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33916?

CVE-2026-33916 is considered a high severity vulnerability due to its potential for prototype-chain traversal.

2

How do I fix CVE-2026-33916?

To fix CVE-2026-33916, update the Handlebars package to version 4.7.9 or later.

3

What versions of Handlebars are affected by CVE-2026-33916?

CVE-2026-33916 affects Handlebars versions from 4.0.0 up to but not including 4.7.9.

4

What is the primary issue with CVE-2026-33916?

The primary issue with CVE-2026-33916 is that it allows for prototype-chain traversal through partial name resolution.

5

Is my application vulnerable if I use Handlebars prior to version 4.7.9?

Yes, if your application uses Handlebars prior to version 4.7.9, it is vulnerable to CVE-2026-33916.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203