
Find real vulnerabilities before they ship
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Base Score
9.8| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| handlebars(npm) | 0 | 4.7.7 | N/A |
| Base Score | 9.8 |
|---|---|
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Base Severity | Critical |
| Version | 3.1 |
| Attack Vector (AV) | NETWORK |