← Back to CVE List

CVE-2019-20920

Published: 2020-09-30T18:15Z
Last Modified: 2024-11-21T04:39Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt