VDB
GHSA-7rx3-28cr-v5wh
GHSA-7rx3-28cr-v5wh
PUBLISHED
CVSS 4.800000190734863 MEDIUM
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | access | |
| AWS | config | |
| npm | handlebars | 4.6.0, 4.6.0, 4.6.0 |
Timeline
- Mar 3, 2026 Security Advisory
- Mar 29, 2026 CVE Published
References
- https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-7rx3-28cr-v5wh url
- https://github.com/advisories/GHSA-765h-qjxv-5f44 advisory
- https://github.com/handlebars-lang/handlebars.js package
- https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9 url
- https://github.com/advisories/GHSA-7rx3-28cr-v5wh advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-23383 vendor-advisory
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427 url
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/handlebars-source/CVE-2021-23383.yml url
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031 url
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030 url
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029 url
- https://www.npmjs.com/package/handlebars url
- https://security.netapp.com/advisory/ntap-20210618-0007 url
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032 url