LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33937

CVE-2026-33937 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 27, 2026

Handlebars - Remote Code Execution

Published: March 27, 2026Updated: March 27, 2026Remote Exploitable

Overview

Handlebars 4.0.0 through 4.7.8 contains a remote code execution caused by unsanitized NumberLiteral AST node value in Handlebars.compile(), letting attackers inject and execute arbitrary JavaScript, exploit requires attacker to supply crafted AST.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary JavaScript on the server, leading to full remote code execution and server compromise.

Mitigation

Upgrade to version 4.7.9 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

šŸ”“ CVE-2026-33937 - Critical (9.8) Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST nod... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33937/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

šŸ”“ CVE-2026-33937 - Critical (9.8) Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST nod... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33937/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33937
Severity
Critical
CVSS Score
9.8
Type
template_injection
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days