CVE-2019-20920

🟠 Łataj w tym tygodniu

Wykonanie dowolnego kodu w Handlebars umożliwia atakującym uruchomienie JavaScript na serwerze lub w przeglądarce.

CVSS
8.1
EPSS
3.2%
Exploit
poc
Vendor
handlebarsjs
Opis źródłowy (NVD)

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

exploit rce xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)3.2%
Opublikowano (NVD)2020-09-30 18:15:17 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:54 UTC
Referencje