StackRadar

CVE-2026-33937

Critical

Advisory

Published 27 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Handlebars.js has JavaScript Injection via AST Type Confusion

Carried by container images the latest versions of 117 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
handlebarsnpm4.0.6, 4.0.10, 4.0.11, 4.0.12+8 more4.7.9109
node-handlebarsdeb3:4.7.7+~4.1.0-1no fix listed1
OSV records
GHSA-2w6w-674q-4c4qUBUNTU-CVE-2026-33937

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
handlebars@4.5.3
4.7.9

Open the chart page →

11,174
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9

Open the chart page →

2,266
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9

Open the chart page →

4,756
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
handlebars@4.7.8
4.7.9

Open the chart page →

64,489
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
handlebars@4.7.8
4.7.9

Open the chart page →

4,650
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
handlebars@4.7.7
4.7.9

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
handlebars@4.7.8
4.7.9

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
handlebars@4.7.8
4.7.9

Open the chart page →

2,973
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
handlebars@4.7.8
4.7.9

Open the chart page →

2,950
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
handlebars@4.7.6
4.7.9

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
handlebars@4.7.7
4.7.9

Open the chart page →

3,451
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
handlebars@4.7.8
4.7.9

Open the chart page →

5,769
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
handlebars@4.7.7
4.7.9

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
handlebars@4.7.8
4.7.9

Open the chart page →

1,271
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
handlebars@4.7.8
4.7.9

Open the chart page →

3,614
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
handlebars@4.1.2
4.7.9

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
handlebars@4.0.11
4.7.9

Open the chart page →

57,669
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
handlebars@4.7.8
4.7.9

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
handlebars@4.7.7
4.7.9

Open the chart page →

4,944
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
handlebars@4.7.7
4.7.9

Open the chart page →

7,232
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
handlebars@4.7.8
4.7.9

Open the chart page →

5,826
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9

Open the chart page →

4,614
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
handlebars@4.7.8
4.7.9

Open the chart page →

914
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
handlebars@4.7.7
4.7.9

Open the chart page →

6,454
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
handlebars@4.7.7
4.7.9

Open the chart page →

4,230
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
handlebars@4.7.8
4.7.9

Open the chart page →

2,548
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
handlebars@4.7.7
4.7.9

Open the chart page →

1,614
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
handlebars@4.7.8
4.7.9

Open the chart page →

3,555
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
handlebars@4.3.5
4.7.9

Open the chart page →

7,929
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
handlebars@4.7.8
4.7.9

Open the chart page →

9,774
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
handlebars@4.7.7
4.7.9

Open the chart page →

5,287
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9

Open the chart page →

10,603
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9

Open the chart page →

19,226
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9

Open the chart page →

2,316
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
handlebars@4.0.10
4.7.9

Open the chart page →

7,048
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
handlebars@4.7.6
4.7.9

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
handlebars@4.7.8
4.7.9

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
handlebars@4.7.8
4.7.9

Open the chart page →

4,960
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
handlebars@4.7.7
4.7.9

Open the chart page →

109,294
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
handlebars@4.7.8
4.7.9

Open the chart page →

2,383
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
handlebars@4.7.6
4.7.9

Open the chart page →

27,465
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
handlebars@4.7.8
4.7.9

Open the chart page →

4,219
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
handlebars@4.4.5
4.7.9

Open the chart page →

1,986
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33937.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
handlebars@4.7.7
4.7.9

Open the chart page →

6,524

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/ghost:5.79.083f7bf209844
handlebars@4.7.8
4.7.9
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
handlebars@4.7.8
4.7.9
1
library/kibana:7.17.150172f1c538e7
handlebars@4.7.7
4.7.9
1
library/kibana:8.18.004c0fc150f3a
handlebars@4.7.8
4.7.9
1
library/kibana:7.17.8c5781ba340ef
handlebars@4.7.7
4.7.9
1
library/kibana:7.17.3e2e2031c15be
handlebars@4.7.7
4.7.9
1
linuxserver/codimd:latestb801bbcf6386
handlebars@4.7.6
4.7.9
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
handlebars@4.7.8
4.7.9
1
mozilla/sentencecollector:2.0.91da6ff5c4895
handlebars@4.7.6
4.7.9
1
n8nio/n8n:1.86.08b39ed5a2de9
handlebars@4.7.8
4.7.9
1
n8nio/n8n:0.212.0a9195bc499a3
handlebars@4.7.7
4.7.9
1
n8nio/n8n:1.33.1dd171d45102a
handlebars@4.7.8
4.7.9
1
nocodb/nocodb:0.258.06779a4ddedf2
handlebars@4.7.8
4.7.9
1
nocodb/nocodb:0.301.5d9516f0bf546
handlebars@4.7.8
4.7.9
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
handlebars@4.7.8
4.7.9
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
handlebars@4.7.7
4.7.9
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
handlebars@4.7.7
4.7.9
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
handlebars@4.4.5
4.7.9
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
handlebars@4.7.8
4.7.9
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
handlebars@4.7.8
4.7.9
1
phntom/codimd:2.4.31b9aafbb62e6
handlebars@4.7.7
4.7.9
1
polonel/trudesk:1.2.60cf6513f6fe3
handlebars@4.7.7
4.7.9
1
qxip/qryn:3.2.3977acc9c7a9fd
handlebars@4.7.8
4.7.9
1
roadiehq/community-backstage-image:latestef355bf5b639
handlebars@4.7.7
4.7.9
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
handlebars@4.7.7
4.7.9
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
handlebars@4.7.7
4.7.9
1
solidproject/community-server:6.0.2ccc4acb7e9a1
handlebars@4.7.7
4.7.9
1
soulteary/cronicle:0.9.80ac2512fa6e39
handlebars@4.7.8
4.7.9
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
handlebars@4.7.7
4.7.9
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
handlebars@4.7.8
4.7.9
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.4.11787550d2358
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
handlebars@4.7.7
4.7.9
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
handlebars@4.7.7
4.7.9
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
handlebars@4.7.7
4.7.9
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
handlebars@4.7.8
4.7.9
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
handlebars@4.7.8
4.7.9
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
handlebars@4.7.8
4.7.9
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
handlebars@4.7.8
4.7.9
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
handlebars@4.7.8
4.7.9
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
handlebars@4.7.8
4.7.9
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
handlebars@4.7.8
4.7.9
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
handlebars@4.7.8
4.7.9
1
ghcr.io/leoquote/mergeable:latest451706815103
handlebars@4.7.6
4.7.9
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
handlebars@4.7.8
4.7.9
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
handlebars@4.7.8
4.7.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.