Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Remediation
References
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478
https://www.npmjs.com/advisories/1316
https://www.npmjs.com/advisories/1324
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-snowflake
CVE-2022-27772 Vulnerability in maven package org.springframework.boot:spring-boot
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-shell
CVE-2016-2510 Vulnerability in maven package org.beanshell:bsh
CVE-2022-31023 Vulnerability in maven package com.typesafe.play:play_2.12