Количество 2
Количество 2
CVE-2026-55760
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL path parameters, request parameters, or other user-controlled sources. This issue is fixed in version 4.5.2.
GHSA-r4gv-qr8j-p3pg
handlebars.java FileTemplateLoader Path Traversal
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55760 Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL path parameters, request parameters, or other user-controlled sources. This issue is fixed in version 4.5.2. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
GHSA-r4gv-qr8j-p3pg handlebars.java FileTemplateLoader Path Traversal | CVSS3: 7.5 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу