Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Remediation
References
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478
https://www.npmjs.com/advisories/1324
https://www.npmjs.com/advisories/1316
Related Vulnerabilities
CVE-2022-31150 Vulnerability in npm package undici
CVE-2019-20343 Vulnerability in maven package org.codehaus.mojo:exec-maven-plugin
CVE-2020-10969 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2016-10622 Vulnerability in npm package nodeschnaps
CVE-2019-12728 Vulnerability in maven package org.grails:grails-core