Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.1
CVE-2026-16231
- EPSS 0.24%
- Veröffentlicht 25.08.2026 10:00:09
- Zuletzt bearbeitet 06.10.2026 22:10:00
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the...
5.3
CVE-2021-32822
- EPSS 1.18%
- Veröffentlicht 16.08.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 06:07:49
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine ...
1