Two high-severity vulnerabilities in Handlebars.js can let attackers execute arbitrary JavaScript on servers by abusing how the template engine handles partials. Tracked as CVE-2026-33938 and CVE-2026-33940, the flaws affect versions 4.0.0 through 4.7.8 and were fixed in 4.7.9. In one case, an attacker can tamper with the special variable @partial-block so that a later {{> @partial-block}} call compiles and runs a crafted Handlebars AST; in the other, a malicious object returned through a dynamic partial lookup can be treated as template input and compiled into executable server-side code.
The vulnerabilities arise from AST type confusion in partial resolution and compilation paths, creating a route from attacker-controlled template data to code generation inside the Handlebars environment. Organizations using Handlebars in server-side rendering or other trusted execution contexts are exposed if untrusted input can influence helpers, context objects, or dynamic partial selection. Defenders are advised to upgrade to Handlebars 4.7.9, prefer the runtime-only build where possible, audit helpers that write to template context, sanitize non-primitive objects from user-controlled data, and avoid third-party helpers or dynamic partial lookups in untrusted workflows.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public advisories described two high-severity Handlebars vulnerabilities: CVE-2026-33938 involving `@partial-block` AST type confusion and CVE-2026-33940 involving dynamic partials accepting crafted objects. Both disclosures noted server-side arbitrary JavaScript or command execution risk and recommended mitigations such as using the runtime-only build and restricting untrusted helper or context input.
Handlebars addressed two vulnerabilities affecting versions 4.0.0 through 4.7.8 in release 4.7.9. One flaw allowed JavaScript injection by tampering with `@partial-block`, and the other allowed attacker-controlled AST compilation through dynamic partial resolution, both leading to arbitrary server-side code execution.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.