CVE-2026-106445
Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
Is your site exposed to CVE-2026-106445?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-106445? +
How do I check if I'm vulnerable to CVE-2026-106445? +
Related Vulnerabilities
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From …
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior …
Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise …
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create …
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature …