CVE-2026-33940 | Handlebars up to 4.7.8 env.compile code injection (GHSA-xhpv-hc6g-r9c6 / Nessus ID 304164)
A vulnerability was found in Handlebars up to 4.7.8 and classified as critical. The affected element is the function env.compile. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2026-33940. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.