CVE-2026-33937 is an improper code-generation vulnerability in Handlebars 4.0.0 through 4.7.8. Handlebars.compile() accepts either a template string or a pre-parsed AST object. When compiling a supplied AST, the compiler emits the value property of a NumberLiteral node directly into generated JavaScript without quoting or sanitization. A crafted AST can therefore inject attacker-controlled JavaScript into the compiled template and cause server-side arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2026-33937, consisting of a README and a single Python script. The exploit targets server-side Handlebars.js 4.0.0 through 4.7.8 and abuses AST injection by supplying a crafted object to Handlebars.compile() instead of a template string. The core technique is implemented in exploit.py: it authenticates to the target web app using a CSRF-protected /login flow, obtains a session cookie, fetches baseline campaign messages from /campaign/1, then submits a JSON request to POST /character with campaign_id=1 and a malicious campaign_message AST. The AST uses a NumberLiteral.value injection inside a lookup helper expression to splice arbitrary JavaScript into the generated template function, ultimately invoking process.mainModule.require('child_process').execSync('/bin/sh -c ... 2>&1').toString() on the Node.js server. The exploit then re-reads /campaign/1 and extracts newly added messages as command output. Capabilities include authenticated arbitrary command execution and output retrieval, with support for complex shell commands, pipes, redirects, and reverse-shell style payloads supplied by the operator. The repository is a real exploit, not merely a detector, and is operational but not framework-based.
Repository is a small standalone Python proof-of-concept for CVE-2026-33937, consisting of README.md and a single executable script, poc.py. The README claims the target is the Hack The Box DarkZeroReturns box and references an earlier public exploit as inspiration. The exploit is a real authenticated web RCE PoC, not merely a detector. It targets a vulnerable Handlebars AST handling path by submitting attacker-controlled structured data in the campaign_message field during character creation. The script builds two variants of a malicious AST: (1) a JSON object payload and (2) a nested application/x-www-form-urlencoded payload using bracket notation. Both variants attempt to abuse Handlebars expression evaluation so that the rendered template executes Node.js code via process.mainModule.require('child_process').execSync(...). Operational flow: the script accepts --base, --campaign, --cmd, and --cookie arguments; defaults to base URL http://dzcampaigns.htb and command id; requires an authenticated cookie either directly or via the DZ_COOKIE environment variable; fetches /character/new to scrape a _csrf token; submits a malicious POST to /character; then checks either the immediate POST response or the campaign page at /campaign/<id> for a random execution marker embedded in command output. This marker-based verification makes the exploit more reliable and reduces false positives. Code structure is straightforward: helper functions extract CSRF tokens, generate the injection string, construct AST objects, flatten nested form fields, print HTTP responses, and search returned HTML for the marker. The exploit does not include persistence, lateral movement, or post-exploitation automation; it is focused on proving arbitrary command execution against the vulnerable web application. Because it includes a working command-execution payload but is not part of a larger exploitation framework, maturity is best classified as OPERATIONAL.
This repository is a self-contained proof-of-concept environment for CVE-2026-33937, demonstrating Handlebars AST injection leading to server-side command execution in a Node.js Express application. The structure includes: (1) app.js, a deliberately vulnerable Express server exposing POST /api/email/preview and compiling user-supplied editorTemplateData with Handlebars 4.7.6; (2) public/index.html, a front-end email preview UI that normally submits template strings to that endpoint; (3) exploit/exploit.py, the main exploit script that sends a crafted AST object instead of a normal template string and injects JavaScript that reaches process.mainModule.require('child_process').execSync(...) for command execution; (4) poc.json, a sample malicious AST payload; and (5) Dockerfile/package files to build and run the vulnerable lab environment. The exploit is interactive: the operator types shell commands, the Python script embeds each command into the malicious AST payload, posts it to the vulnerable endpoint, and prints returned command output from the html field of the JSON response. This is an actual exploit rather than a detector, and it provides practical RCE capability against the demo service. The Docker configuration also exposes the Node inspector on 9229, which is notable operationally but separate from the Handlebars exploit path.
This repository is a small Node.js research lab/PoC environment demonstrating alleged CVE-2026-33937, described as a Handlebars AST type-confusion/code-generation issue leading to RCE. It is not a framework module; it is a standalone Express application intentionally exposing unsafe rendering behavior. Repository structure: server.js is the main runnable application. It starts an Express server, exposes GET / for a simple HTML form, and POST /render for the vulnerable flow. The POST handler parses req.body.payload as JSON, treats it as a Handlebars AST object, and passes it directly to Handlebars.compile(payload). The compiled template is then executed with a small context object and the result or stack trace is returned to the client. This is the clearest exploit path in the repo. There is also a secondary modularized implementation under src/routes/render.route.js and src/services/render.service.js. The service supports two modes: inputType=template for normal template strings and inputType=ast for direct AST objects. The ast branch again calls Handlebars.compile(payload) on attacker-controlled object input, preserving the same dangerous behavior. However, these route files do not appear wired into server.js in the provided snapshot, so they look like alternate or future API structure rather than the active entry point. The README explains the intended vulnerability chain: attacker supplies a crafted AST, Handlebars accepts object input as pre-parsed AST, and a malicious NumberLiteral.value is allegedly emitted unsafely into generated JavaScript, resulting in arbitrary JavaScript execution when the generated function is evaluated. The included PoC AST shows the injection concept. The exploit capability is therefore server-side RCE through malicious JSON submitted to the render endpoint. Operationally, the repo includes Dockerfile and docker-compose.yml to package the lab. The Dockerfile installs dependencies, copies the app, and copies a local flag.txt into /flag.txt, strongly indicating a CTF/lab validation target for successful code execution. docker-compose exposes the service on host port 3001 mapped to container port 3000. deploy.sh automates cloning and rebuilding the containerized app. Overall purpose: this repository is an intentionally vulnerable demonstration environment for exploiting unsafe Handlebars AST compilation in a Node.js web service. Its main capability is accepting remote HTTP input that can be transformed into arbitrary JavaScript execution in the server process, with likely post-exploitation access to container-local artifacts such as /flag.txt.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.