VYPR

handlebars-springmvc

by JKnack

CVEs (1)

  • CVE-2026-103088HigSep 30, 2026
    risk 0.42cvss 7.5epss —

    Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that…