VYPR

Handlebars

by JKnack

CVEs (1)

  • CVE-2026-55760higJun 17, 2026
    risk 0.38cvss epss

    ### Impact Any application that passes user-controlled input to Handlebars.compile() using a FileTemplateLoader (or ClassPathTemplateLoader) is vulnerable to arbitrary file read. This is a realistic attack surface for web applications that use template names from URL path…