CVE-2021-23369 is a remote code execution vulnerability in the Handlebars JavaScript templating package before version 4.7.7. Compiling a template obtained from an untrusted source with the strict: true compilation option can permit attacker-controlled template content to execute code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
strict: true compile option for any template that may be attacker controlled, and enforce trusted-template provenance and input validation.Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Node.js proof-of-concept application demonstrating exploitation conditions for CVE-2021-23369 in handlebars 4.7.6. The core logic is entirely in server.js: an Express server exposes GET / to present a form and POST /render to accept a user-supplied tpl parameter, compile it with Handlebars.compile(..., {strict:true}), and render it with a simple context object. Because template input is fully attacker-controlled, the application is intentionally vulnerable as an SSTI-style demo. The server returns either rendered output or full exception stack traces, which increases exploitability for testing. Repository structure is minimal and purpose-built: package.json and package-lock.json define the Node dependencies; Dockerfile builds a containerized demo and copies /flag.txt into the image; docker-compose.yml exposes the service on host port 3002; deploy.sh automates cloning, pulling, rebuilding, and restarting the containerized app under /opt/cve-2021-23369. There is no standalone exploit client script, scanner, or weaponized payload generator in the repository. Instead, the repository itself is the vulnerable target environment used to manually test crafted Handlebars payloads against the /render endpoint. Overall, this is a real exploit lab/POC repository rather than a detection script. Its main capability is to provide a reproducible vulnerable web service that accepts malicious template expressions over HTTP for demonstrating CVE-2021-23369 behavior.
This repository provides a proof-of-concept exploit and a scanner for CVE-2021-23369, a remote code execution vulnerability in Handlebars versions before 4.7.7. The main exploit file, 'handlebars_exploit.py', allows a user to input a target URL, then sends a specially crafted Handlebars template via HTTP POST to the target, attempting to trigger the vulnerability and execute arbitrary code. The payload is a complex Handlebars template designed to exploit the vulnerability. The 'handlebars_scanner.py' script is a simple detection tool that checks if the target server is potentially running Handlebars by inspecting the 'Server' HTTP header. The repository is structured with a README, the exploit script, and the scanner script. No hardcoded endpoints are present; all targets are user-supplied at runtime. The exploit is a POC and does not provide a weaponized or customizable payload beyond the demonstration template.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compiling untrusted templates with strict:true in nodejs-handlebars can result in remote code execution.
A remote-code-execution vulnerability when nodejs-handlebars compiles untrusted templates using the strict:true option.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.