CVE-2021-23383 PUBLISHED

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

EPSS 3.18% · 86.9th percentile

Risk Scores

EPSS Score
3.18%
86.9th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10node-handlebars0, 3:4.7.7+~4.1.0-1
Ubuntu:20.04:LTSnode-handlebars0, *, 3:4.5.3-1
Ubuntu:24.04:LTSnode-handlebars3:4.7.7+~4.1.0-1, 0
Ubuntu:22.04:LTSnode-handlebars0, 3:4.7.6+~4.1.0-2, 3:4.7.7+~4.1.0-1
Ubuntu:18.04:LTSnode-handlebars0, *

Timeline

References

Open in Interactive Console →