CVE-2019-19919
9.8
CRITICAL · CVSS 3.1 · EPSS 7.1% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.07% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-1321 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-12-20 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| handlebars.js project | handlebars.js |
| tenable | tenable.sc |
References
→ the Explorer · watch your stack · NVD