Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0.6-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.7-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.8-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.9-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.10-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.11-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.12-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.3-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.4-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.5-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.6-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.7-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.3-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.4-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.5-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.6-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.7-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.8-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.9-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.10-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.11-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.12-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.13-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.14-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.2-NA"
}
]
}