REDHAT-BUG-2452524: High severity Handlebars Handlebars CLI precompiler vulnerability
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (bin/handlebars / lib/precompiler.js) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values that contain characters with JavaScript string-escaping significance (", ', ;, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated build pipeline.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Handlebars CLI precompiler (bin/handlebars / lib/precompiler.js)to a version that resolves this vulnerability.Fixed in 4.7.9 - Configuration
Before invoking the precompiler, validate CLI inputs (template filenames and all CLI option values) and reject any that contain characters with JavaScript string-escaping significance such as ", ', ;, etc.
Handlebars CLI precompiler Input validation for CLI arguments and template filenames = Reject any filenames/option values containing JavaScript string-escaping significance characters (e.g., ", ', ;, etc.) - Configuration
In automated pipelines, pass the fixed trusted namespace string via a configuration file rather than through CLI arguments.
Automated build pipeline configuration for Handlebars namespace Namespace source = Use a fixed, trusted namespace string from a configuration file instead of command-line arguments - Compensating control
Run the Handlebars precompiler in a sandboxed environment (e.g., a container with no write access to sensitive paths) to limit impact if exploitation succeeds.
- Operational
Audit template filenames in any repository or package consumed by an automated build pipeline.