Vulnerability Description
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL path parameters, request parameters, or other user-controlled sources. This issue is fixed in version 4.5.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/jknack/handlebars.java/commit/d177cdee8b750385ca7a0d0f89f2d4b
- https://github.com/jknack/handlebars.java/releases/tag/v4.5.2
- https://github.com/jknack/handlebars.java/security/advisories/GHSA-r4gv-qr8j-p3p
FAQ
What is CVE-2026-55760?
CVE-2026-55760 is a vulnerability with a CVSS score of 7.5 (HIGH). Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPat...
How severe is CVE-2026-55760?
CVE-2026-55760 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55760?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.