vulnerability

Red Hat: CVE-2021-23369: nodejs-handlebars: Remote code execution when compiling untrusted compile templates with strict:true option

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Apr 12, 2021
Added
Jul 9, 2025
Modified
Jul 9, 2025

Description

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Solution

no-fix-redhat-rpm-package
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.