CVE-2026-103088 Details
Description
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.
A directory traversal vulnerability has been identified in Handlebars.java versions prior to 4.5.5, specifically within the Handlebars-SpringMVC component in versions 4.5.3 and 4.5.4. The issue arises from a path-containment fix in version 4.5.3 that improperly validates template locations as raw percent-encoded strings. When the template file is accessed through a URL handler that decodes the path, this validation flaw allows for traversal attacks that bypass both the view-resolver check and the loader-side containment, enabling access to files outside the designated template base directory.
Users can upgrade to Handlebars.java version 4.5.5, which addresses the vulnerability by properly validating and handling percent-encoded paths before accessing files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/jknack/handlebars.java/commit/f6ae3979917d05bef07f00befb4013ef00503660 | [email protected] | Source CodeVendor |
| https://github.com/jknack/handlebars.java/releases/tag/v4.5.5 | [email protected] | Release NotesVendor |
| https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-24 | Path Traversal: '../filedir' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| com.github.jknack.handlebars.java | >= 4.5.3, <= 4.5.4 (semver) |
CPE
Remediation
| |
| com.github.jknack.handlebars-springmvc | 4.5.3 (semver) 4.5.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion