lowCVSS 3.7Vulnerability

GHSA-442j-39wm-28r2

## Summary In `lib/handlebars/runtime.js`, the `container.lookup()` function uses `container.lookupProperty()` as a gate check to enforce prototype-access controls, but then discards the validated result and performs a second, unguarded property access (`depths[i][name]`). This Time-of-Check Time-of-Use (TOCTOU) pattern means the security check and the actual read are decoupled, and the raw access bypasses any sanitization that `lookupProperty` may perform. Only relevant when the **compat** compile option is enabled (`{compat: true}`), which activates `depthedLookup` in `lib/handlebars/compiler/javascript-compiler.js`. ## Description The vulnerable code in `lib/handlebars/runtime.js` (lines 137–144): ```javascript lookup: function (depths, name) { const len = depths.length; for (let i = 0; i < len; i++) { let result = depths[i] && container.lookupProperty(depths[i], name); if (result != null) { return depths[i][name]; // BUG: should be `return result;` } } }, ``` `container.lookupProperty()` (lines 119–136) enforces `hasOwnProperty` checks and `resultIsAllowed()` prototype-access controls. However, `container.lookup()` only uses `lookupProperty` as a boolean gate — if the gate passes (`result != null`), it then performs an independent, raw `depths[i][name]` access that circumvents any transformation or wrapped value that `lookupProperty` may have returned. ## Workarounds - Avoid enabling `{ compat: true }` when rendering templates that include untrusted data. - Ensure context data objects are plain JSON (no Proxies, no getter-based accessor properties).

Properties

ghsa_id
GHSA-442j-39wm-28r2
severity
low
summary
Handlebars.js has a Property Access Validation Bypass in container.lookup
cvss_score
3.7
cve_id
GHSA-442j-39wm-28r2
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-03-29T15:16:37Z
source_url
https://github.com/advisories/GHSA-442j-39wm-28r2
ghsa_updated
2026-03-29T15:16:37Z

Related Entities (3)

AFFECTS (1)

[Software]npm/handlebars

HAS_WEAKNESS (1)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-442j-39wm-28r2 (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal