Handlebars Prototype Deny-List Bypass Enables Remote Code Execution (CVE-2026-106445)
What happened
A GitHub Security Advisory (GHSA-p8wg-vrv2-v86f) discloses a vulnerability in Handlebars, the widely used JavaScript templating engine, tracked as CVE-2026-106445. According to the advisory, Handlebars' lookupProperty function checks whether a property is an "own property" of an object before consulting its prototype-access deny list. Because constructor is itself an own property of prototype objects (e.g. Function.prototype.constructor === Function), a template that reaches Function.prototype can retrieve the Function constructor without ever triggering the deny-list check that normally blocks it.
The advisory includes a working proof-of-concept that chains Handlebars helpers (lookup, #with, #each, apply) to reach Function.prototype, extract its constructor, and use it to build and execute an arbitrary function body — demonstrated running child_process.execSync on the host. This requires the template to be compiled with allowProtoMethodsByDefault: true and for the attacker to control the rendered template and/or its data.
Why it matters for defenders
Handlebars is embedded in a large number of Node.js applications, server-side rendering pipelines, and email/document-generation tools. Per the advisory, the precondition is use of allowProtoMethodsByDefault: true when compiling templates with untrusted input — a non-default but not uncommon configuration, particularly where applications relaxed Handlebars' proto protections to support legitimate prototype method access. Any service rendering user-supplied or externally-sourced templates under that setting is exposed to server-side remote code execution, with the demonstrated impact equivalent to arbitrary command execution as the Node process user.
What to watch for / do now
- Audit all Handlebars
compile()/precompile()call sites forallowProtoMethodsByDefault: true, and remove it unless the templates and data are fully trusted. - Inventory where template strings or template context data originate from untrusted sources (user input, third-party content, uploaded files) and treat any such path with this option enabled as high risk.
- Watch for anomalous child-process spawns from Node.js services that perform template rendering — this class of bug ultimately manifests as unexpected shell/process execution from an application server.
- Review application and WAF logs for template payloads referencing
lookup,__proto__,constructor, orapplyin combination within Handlebars-rendered fields. - Upgrade Handlebars once a patched release addressing this advisory is available, and track the package version in use across services.
Developing intel
This is a same-day advisory and the full technical details, including the complete proof-of-concept, are documented in the original GHSA. No CVSS score or ransomware-campaign association has been published yet, and exploit status is currently proof-of-concept only. Defenders should treat this as developing intelligence and consult the source directly: GHSA-p8wg-vrv2-v86f.