The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "handlebars" }, { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "libjs-handlebars" }, { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "libjs-handlebars.runtime" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "handlebars" }, { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "libjs-handlebars" }, { "binary_version": "3:4.7.7+~4.1.0-1", "binary_name": "libjs-handlebars.runtime" } ] }