Handlebars.precompile() generates JavaScript source that is commonly embedded in browser <script> elements. Before the fix, static template text containing </script> was emitted unchanged. HTML parsers recognize </script> even inside a JavaScript string literal, closing the surrounding script element and allowing following attacker-controlled markup to be parsed and executed.
This affects applications that precompile attacker-controlled templates and embed the generated source directly in an HTML <script> element. It does not affect ordinary server-side rendering or precompiled templates delivered as external JavaScript files.
Static text is serialized by quotedString() in lib/handlebars/compiler/code-gen.js. The generated JavaScript is valid, but JavaScript quoting alone does not make it safe to embed in HTML. In HTML script data, the sequence </script> terminates the element regardless of JavaScript string context.
On affected releases, this template:
safe</script><script>alert("XSS")</script><script>
could produce generated source containing:
return 'safe</script><script>alert("XSS")</script><script>';
When included inline in an HTML document, the first </script> closes the script containing the precompiled template. The next <script> element is then parsed as HTML and executes.
const Handlebars = require('handlebars');
const template = 'safe</script><script>alert("XSS")</script><script>';
const output = Handlebars.precompile(template);
console.log(output.includes('</script>'));
Affected versions print true. Embedding output directly in an inline <script> element allows the injected script tag to be parsed by the browser.
Reported by Curly-Haired-Baboon Aka Laplas
{
"cwe_ids": [
"CWE-116"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T17:52:37Z",
"nvd_published_at": "2026-10-06T20:17:26Z",
"severity": "MODERATE"
}