Generated remediation guidance and an executive summary. No account required.
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Cite this page
CVE-2019-20920. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-20920
Use CWE-94, Handlebarsjs vendor hub and Handlebars product page to widen CVE-2019-20920 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33937, CVE-2026-33941 and CVE-2026-33940 for nearby disclosures in the same product family.