The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3:4.0.10-5", "binary_name": "handlebars" }, { "binary_version": "3:4.0.10-5", "binary_name": "libjs-handlebars" }, { "binary_version": "3:4.0.10-5", "binary_name": "libjs-handlebars.runtime" } ] }