peter bassill · operator
$ cve CVE-2019-19919 JSON

CVE-2019-19919

9.8
CRITICAL · CVSS 3.1 · EPSS 7.1% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.07% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-1321
On CISA KEVno
Public exploitnone known
Published2019-12-20
Last modified2026-06-17

Affected (2)

VendorProduct
handlebars.js projecthandlebars.js
tenabletenable.sc

References

→ the Explorer  ·  watch your stack  ·  NVD