Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
77%
Total Score
36
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33938 handlebars is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 4.0.0 - 4.7.8. | 4.0.0 - 4.7.8 | High |
CVE-2026-33937 handlebars is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 4.0.0 - 4.7.8. | 4.0.0 - 4.7.8 | Critical |
CVE-2026-33941 handlebars is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.7.8. | 4.0.0 - 4.7.8 | High |
CVE-2026-33940 handlebars is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 4.0.0 - 4.7.8. | 4.0.0 - 4.7.8 | High |
CVE-2026-33939 handlebars is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 4.0.0 - 4.7.8. | 4.0.0 - 4.7.8 | High |
| Dependency | Last Release | Score |
|---|---|---|
minimist Version ^1.2.5 | — | — |
wordwrap Version ^1.0.0 | — | — |
neo-async Version ^2.6.2 | — | — |
uglify-js Version ^3.1.4 | — | — |
source-map Version ^0.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant