StackRadar

CVE-2026-33940

High

Advisory

Published 27 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Carried by container images the latest versions of 117 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
handlebarsnpm4.0.6, 4.0.10, 4.0.11, 4.0.12+8 more4.7.9109
node-handlebarsdeb3:4.7.7+~4.1.0-1no fix listed1
OSV records
GHSA-xhpv-hc6g-r9c6UBUNTU-CVE-2026-33940

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
handlebars@4.7.8
4.7.9

Open the chart page →

2,969
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
handlebars@4.7.8
4.7.9
fonoster/routr-dispatcher:2.13.65f8f380dc174
handlebars@4.7.8
4.7.9
fonoster/routr-location:2.13.6051ba9c34ef5
handlebars@4.7.8
4.7.9
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
handlebars@4.7.8
4.7.9
fonoster/routr-registry:2.13.6e27001f2813c
handlebars@4.7.8
4.7.9

Open the chart page →

11,021
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
handlebars@4.7.7
4.7.9

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

16,620
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
handlebars@4.7.8
4.7.9

Open the chart page →

1,991
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
handlebars@4.7.7
4.7.9

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
handlebars@4.7.7
4.7.9

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
handlebars@4.7.7
4.7.9

Open the chart page →

3,576
saleor-appstrieb-work0.6.02 of 5See more

saleor-apps trieb-work 0.6.0

2 of the 5 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
handlebars@4.7.7
4.7.9
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
handlebars@4.7.7
4.7.9

Open the chart page →

6,994
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
handlebars@4.7.7
4.7.9

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
handlebars@4.7.8
4.7.9

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
handlebars@4.7.6
4.7.9

Open the chart page →

5,806
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
handlebars@4.7.7
4.7.9

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33940.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
handlebars@4.7.7
4.7.9

Open the chart page →

9,381

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/ghost:5.79.083f7bf209844
handlebars@4.7.8
4.7.9
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
handlebars@4.7.8
4.7.9
1
library/kibana:7.17.150172f1c538e7
handlebars@4.7.7
4.7.9
1
library/kibana:8.18.004c0fc150f3a
handlebars@4.7.8
4.7.9
1
library/kibana:7.17.8c5781ba340ef
handlebars@4.7.7
4.7.9
1
library/kibana:7.17.3e2e2031c15be
handlebars@4.7.7
4.7.9
1
linuxserver/codimd:latestb801bbcf6386
handlebars@4.7.6
4.7.9
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
handlebars@4.7.8
4.7.9
1
mozilla/sentencecollector:2.0.91da6ff5c4895
handlebars@4.7.6
4.7.9
1
n8nio/n8n:1.86.08b39ed5a2de9
handlebars@4.7.8
4.7.9
1
n8nio/n8n:0.212.0a9195bc499a3
handlebars@4.7.7
4.7.9
1
n8nio/n8n:1.33.1dd171d45102a
handlebars@4.7.8
4.7.9
1
nocodb/nocodb:0.258.06779a4ddedf2
handlebars@4.7.8
4.7.9
1
nocodb/nocodb:0.301.5d9516f0bf546
handlebars@4.7.8
4.7.9
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
handlebars@4.7.8
4.7.9
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
handlebars@4.7.7
4.7.9
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
handlebars@4.7.7
4.7.9
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
handlebars@4.7.7
4.7.9
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
handlebars@4.4.5
4.7.9
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
handlebars@4.7.8
4.7.9
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
handlebars@4.7.8
4.7.9
1
phntom/codimd:2.4.31b9aafbb62e6
handlebars@4.7.7
4.7.9
1
polonel/trudesk:1.2.60cf6513f6fe3
handlebars@4.7.7
4.7.9
1
qxip/qryn:3.2.3977acc9c7a9fd
handlebars@4.7.8
4.7.9
1
roadiehq/community-backstage-image:latestef355bf5b639
handlebars@4.7.7
4.7.9
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
handlebars@4.7.7
4.7.9
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
handlebars@4.7.7
4.7.9
1
solidproject/community-server:6.0.2ccc4acb7e9a1
handlebars@4.7.7
4.7.9
1
soulteary/cronicle:0.9.80ac2512fa6e39
handlebars@4.7.8
4.7.9
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
handlebars@4.7.7
4.7.9
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
handlebars@4.7.8
4.7.9
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.4.11787550d2358
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
handlebars@4.7.7
4.7.9
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
handlebars@4.7.7
4.7.9
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
handlebars@4.7.7
4.7.9
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
handlebars@4.7.7
4.7.9
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
handlebars@4.7.8
4.7.9
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
handlebars@4.7.8
4.7.9
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
handlebars@4.7.8
4.7.9
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
handlebars@4.7.8
4.7.9
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
handlebars@4.7.8
4.7.9
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
handlebars@4.7.8
4.7.9
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
handlebars@4.7.8
4.7.9
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
handlebars@4.7.8
4.7.9
1
ghcr.io/leoquote/mergeable:latest451706815103
handlebars@4.7.6
4.7.9
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
handlebars@4.7.8
4.7.9
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
handlebars@4.7.8
4.7.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.