CVE-2026-33940
A flaw was found in Handlebars.js. A remote attacker can exploit this vulnerability by providing a specially crafted object within the template context. This crafted object, when processed by a dynamic partial lookup, can bypass security checks and be interpreted as malicious code. This allows the attacker to execute arbitrary commands on the server where Handlebars.js is running.
- Vendor
- Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, handlebars-lang, Red Hat
- Product
- Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat Data Grid 8, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Cryostat 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Process Automation 7, Red Hat Enterprise Linux 7, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, handlebars.js, Red Hat Enterprise Linux 8
- Provider severity
- HIGH
- Conflicts
- 2