Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The lockfile pins handlebars 4.7.8, and the finding indicates multiple known critical advisories affecting that version, including prototype pollution and template/AST-driven code or script injection paths. In an invoice-generation skill, templating libraries often process user-supplied invoice data and possibly templates, so exploitation could lead to XSS in rendered HTML/PDF workflows, data tampering, or code execution within the templating context depending on how the library is used.
- Content
