High severity7.5NVD Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-55760
CVE-2026-55760
Description
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL path parameters, request parameters, or other user-controlled sources. This issue is fixed in version 4.5.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.github.jknack:handlebarsMaven | < 4.5.2 | 4.5.2 |
Affected products
2- Range: <4.5.2
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.