← Blog · · df00tech

Handlebars Prototype Deny-List Bypass Enables Remote Code Execution (CVE-2026-106445)

breaking ghsa npm CVE-2026-106445

What happened

A GitHub Security Advisory (GHSA-p8wg-vrv2-v86f) discloses a vulnerability in Handlebars, the widely used JavaScript templating engine, tracked as CVE-2026-106445. According to the advisory, Handlebars' lookupProperty function checks whether a property is an "own property" of an object before consulting its prototype-access deny list. Because constructor is itself an own property of prototype objects (e.g. Function.prototype.constructor === Function), a template that reaches Function.prototype can retrieve the Function constructor without ever triggering the deny-list check that normally blocks it.

The advisory includes a working proof-of-concept that chains Handlebars helpers (lookup, #with, #each, apply) to reach Function.prototype, extract its constructor, and use it to build and execute an arbitrary function body — demonstrated running child_process.execSync on the host. This requires the template to be compiled with allowProtoMethodsByDefault: true and for the attacker to control the rendered template and/or its data.

Why it matters for defenders

Handlebars is embedded in a large number of Node.js applications, server-side rendering pipelines, and email/document-generation tools. Per the advisory, the precondition is use of allowProtoMethodsByDefault: true when compiling templates with untrusted input — a non-default but not uncommon configuration, particularly where applications relaxed Handlebars' proto protections to support legitimate prototype method access. Any service rendering user-supplied or externally-sourced templates under that setting is exposed to server-side remote code execution, with the demonstrated impact equivalent to arbitrary command execution as the Node process user.

What to watch for / do now

  • Audit all Handlebars compile()/precompile() call sites for allowProtoMethodsByDefault: true, and remove it unless the templates and data are fully trusted.
  • Inventory where template strings or template context data originate from untrusted sources (user input, third-party content, uploaded files) and treat any such path with this option enabled as high risk.
  • Watch for anomalous child-process spawns from Node.js services that perform template rendering — this class of bug ultimately manifests as unexpected shell/process execution from an application server.
  • Review application and WAF logs for template payloads referencing lookup, __proto__, constructor, or apply in combination within Handlebars-rendered fields.
  • Upgrade Handlebars once a patched release addressing this advisory is available, and track the package version in use across services.

Developing intel

This is a same-day advisory and the full technical details, including the complete proof-of-concept, are documented in the original GHSA. No CVSS score or ransomware-campaign association has been published yet, and exploit status is currently proof-of-concept only. Defenders should treat this as developing intelligence and consult the source directly: GHSA-p8wg-vrv2-v86f.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.