REDHAT-BUG-2452525: High severity npm/handlebars vulnerability
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the @partial-block special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper overwrites @partial-block with a crafted Handlebars AST, a subsequent invocation of {{> @partial-block}} compiles and executes that AST, enabling arbitrary JavaScript execution on the server. Version 4.7.9 fixes the issue. Some workarounds are available. First, use the runtime-only build (require('handlebars/runtime')). The compile() method is absent, eliminating the vulnerable fallback path. Second, audit registered helpers for any that write arbitrary values to context objects. Helpers should treat context data as read-only. Third, avoid registering helpers from third-party packages (such as handlebars-helpers) in contexts where templates or context data can be influenced by untrusted input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.9 - Configuration
Update any registered Handlebars helpers to treat context data as read-only; audit registered helpers and remove/modify any that write arbitrary values to context objects (especially anything that could overwrite or mutate @partial-block).
Handlebars helpers helper implementation (read-only context) = treat context data as read-only - Configuration
Avoid registering helpers from third-party packages (such as handlebars-helpers) in contexts where templates or context data can be influenced by untrusted input.
Handlebars helper registration register third-party helpers (e.g., handlebars-helpers) = do not register in untrusted contexts - Compensating control
Use the runtime-only build by changing code to require('handlebars/runtime') to avoid the vulnerable fallback path (notably the absence of compile()).