The GitHub Advisory Database published a security advisory on 8 October 2026 about Handlebars, a JavaScript templating library. It says the compile() and precompile() functions can be tricked into running attacker code. Both functions accept a template string or a pre-parsed template tree, known as an AST. Version 4.7.9 added checks for such trees. The advisory says those checks cover only some value types, so the compiler still writes other values into its generated code unchecked. It credits Thai Son Dinh of VinSOC Labs.
An app is affected only if untrusted input reaches either function as an object, such as a parsed JSON request body. With compile(), the advisory says the injected code runs on the server with the app's privileges when the template renders. With precompile(), the code lands in the output and runs wherever that output is loaded. Apps that pass only strings are not affected. The advisory does not say how many apps are exposed or whether attacks have occurred. It links to release v4.7.10 but does not state that this release fixes the flaw.
Teams running Node.js servers with Handlebars should check whether request data can reach compile() or precompile() as an object. The advisory suggests rejecting any input that is not a string, or using the runtime-only build if templates are compiled ahead of time.