Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Remediation
References
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478
https://www.npmjs.com/advisories/1316
https://www.npmjs.com/advisories/1324
Related Vulnerabilities
CVE-2020-5219 Vulnerability in maven package org.webjars.npm:angular-expressions
CVE-2017-2654 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-media-embed
CVE-2014-6393 Vulnerability in maven package org.webjars.npm:express
CVE-2018-11799 Vulnerability in maven package org.apache.oozie:oozie-core