CVE-2019-19919 PUBLISHED

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

EPSS 17.80% · 95.1th percentile

Risk Scores

EPSS Score
17.80%
95.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-handlebars0, 3:4.0.10-5

Timeline

References

Open in Interactive Console →