vulnerability

Red Hat: CVE-2021-23383: nodejs-handlebars: Remote code execution when compiling untrusted compile templates with compat:true option

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
May 4, 2021
Added
Jul 9, 2025
Modified
Jul 9, 2025

Description

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

Solution

no-fix-redhat-rpm-package
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.