# CVE-2026-63490

## Summary

- **CVE ID:** CVE-2026-63490
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-22, CWE-23, CWE-552
- **Published:** Aug 20, 2026
- **Last Modified:** Aug 25, 2026

## Description

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/SpringTemplateLoader.java, a view name using a file: or classpath: URL and ending with the # fragment delimiter places the appended .hbs suffix in the fragment, which FileUrlResource.exists() and URL.openStream() discard. HandlebarsViewResolver in handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/HandlebarsViewResolver.java then passes the attacker-controlled name to handlebars.compile(), allowing an unauthenticated remote attacker to read files accessible to the JVM when an application exposes a controller with a user-influenced view name. This issue is fixed in version 4.5.3.

## Affected Products

- jknack — handlebars.java (< 4.5.3)

## References

- [CNA](https://github.com/jknack/handlebars.java/security/advisories/GHSA-g29j-rwfv-h99w)
- [CNA](https://github.com/jknack/handlebars.java/commit/61f43423a337b87db5fec1fe59f0725aaaa38df5)
- [CNA](https://github.com/jknack/handlebars.java/releases/tag/v4.5.3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.47%
- **EPSS Percentile:** 39.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._