{"id":"GHSA-w457-6q6x-cgp9","summary":"Prototype Pollution in handlebars","details":"Versions of `handlebars` prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' `__proto__` and `__defineGetter__` properties, which may allow an attacker to execute arbitrary code through crafted payloads.\n\n\n## Recommendation\n\nUpgrade to version 3.0.8, 4.3.0 or later.","aliases":["CVE-2019-19919"],"modified":"2026-07-17T21:08:05.262507509Z","published":"2019-12-26T17:58:13Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-12-26T17:55:40Z","nvd_published_at":"2019-12-20T23:15:00Z","cwe_ids":["CWE-1321","CWE-74"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19919"},{"type":"WEB","url":"https://github.com/wycats/handlebars.js/issues/1558"},{"type":"WEB","url":"https://github.com/handlebars-lang/handlebars.js/commit/156061eb7707575293613d7fdf90e2bdaac029ee"},{"type":"WEB","url":"https://github.com/handlebars-lang/handlebars.js/commit/90ad8d97ad2933852fb83fcc054699dc99e094db"},{"type":"WEB","url":"https://github.com/wycats/handlebars.js/commit/2078c727c627f25d4a149962f05c1e069beb18bc"},{"type":"WEB","url":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19919"},{"type":"WEB","url":"https://github.com/Nerian/bootstrap-wysihtml5-rails/blob/master/vendor/assets/javascripts/bootstrap-wysihtml5/handlebars.runtime.min.js"},{"type":"WEB","url":"https://github.com/Nerian/bootstrap-wysihtml5-rails/tree/master/vendor/assets/javascripts/bootstrap-wysihtml5"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap-wysihtml5-rails/CVE-2019-19919.yml"},{"type":"PACKAGE","url":"https://github.com/wycats/handlebars.js"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2021-14"}],"affected":[{"package":{"name":"handlebars","ecosystem":"npm","purl":"pkg:npm/handlebars"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/12/GHSA-w457-6q6x-cgp9/GHSA-w457-6q6x-cgp9.json"}},{"package":{"name":"bootstrap-wysihtml5-rails","ecosystem":"RubyGems","purl":"pkg:gem/bootstrap-wysihtml5-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.3.5"},{"last_affected":"0.3.3.8"}]}],"versions":["0.3.3.5","0.3.3.6","0.3.3.7","0.3.3.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/12/GHSA-w457-6q6x-cgp9/GHSA-w457-6q6x-cgp9.json"}},{"package":{"name":"handlebars","ecosystem":"npm","purl":"pkg:npm/handlebars"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/12/GHSA-w457-6q6x-cgp9/GHSA-w457-6q6x-cgp9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}