StackRadar

CVE-2026-55760

High

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 1
affected package

handlebars.java FileTemplateLoader Path Traversal

Carried by container images the latest versions of 27 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
handlebarsmaven4.1.2, 4.2.0, 4.3.1, 4.4.0+1 more4.5.225
OSV records
GHSA-r4gv-qr8j-p3pg

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
metabasepmint932.27.61 of 1See more

metabase pmint93 2.27.6

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
handlebars@4.3.1
4.5.2

Open the chart page →

1,639
thehivestrangebee-helmOfficialVerified publisher1.0.61 of 7See more

thehive strangebee-helm 1.0.6

1 of the 7 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
strangebee/thehive:5.7.6-1e77b713124dd
handlebars@4.3.1
4.5.2

Open the chart page →

16,210
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
handlebars@4.2.0
4.5.2

Open the chart page →

17,896
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
handlebars@4.1.2
4.5.2

Open the chart page →

2,140
featurehubfeaturehub4.1.61 of 7See more

featurehub featurehub 4.1.6

1 of the 7 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
featurehub/mr:1.9.1477d8bf771a9
handlebars@4.3.1
4.5.2

Open the chart page →

8,240
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
handlebars@4.5.0
4.5.2

Open the chart page →

31,844
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
handlebars@4.3.1
4.5.2

Open the chart page →

467
edge-caiasoftfolio-org0.1.321 of 1See more

edge-caiasoft folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/edge-caiasoft:latestc3cfa89eee2f
handlebars@4.3.1
4.5.2

Open the chart page →

525
edge-dematicfolio-org0.1.331 of 1See more

edge-dematic folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/edge-dematic:latest48c9b1d180d4
handlebars@4.3.1
4.5.2

Open the chart page →

525
edge-inn-reachfolio-org0.1.41 of 1See more

edge-inn-reach folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/edge-inn-reach:latestc64e4d9dd3fc
handlebars@4.3.1
4.5.2

Open the chart page →

525
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
handlebars@4.3.1
4.5.2

Open the chart page →

1,259
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
handlebars@4.3.1
4.5.2

Open the chart page →

415
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
handlebars@4.3.1
4.5.2

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
handlebars@4.3.1
4.5.2

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
handlebars@4.3.1
4.5.2

Open the chart page →

1,214
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
handlebars@4.3.1
4.5.2

Open the chart page →

1,203
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
handlebars@4.3.1
4.5.2

Open the chart page →

512
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
handlebars@4.3.1
4.5.2

Open the chart page →

156
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
handlebars@4.3.1
4.5.2

Open the chart page →

394
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
handlebars@4.3.1
4.5.2

Open the chart page →

571
mod-tagsfolio-org0.1.341 of 1See more

mod-tags folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
folioci/mod-tags:latest6e8beeb70272
handlebars@4.3.1
4.5.2

Open the chart page →

342
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
handlebars@4.1.2
4.5.2

Open the chart page →

2,140
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
handlebars@4.2.0
4.5.2

Open the chart page →

2,427
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
handlebars@4.3.1
4.5.2

Open the chart page →

2,589
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
handlebars@4.4.0
4.5.2

Open the chart page →

5,826
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
handlebars@4.4.0
4.5.2

Open the chart page →

7,637
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-55760.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
handlebars@4.3.1
4.5.2

Open the chart page →

1,639

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
metabase/metabase:v0.61.1.x9491ed11c901
handlebars@4.3.1
4.5.2
2
rodolpheche/wiremock:2.26.03be08a386092
handlebars@4.1.2
4.5.2
2
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
handlebars@4.2.0
4.5.2
1
featurehub/mr:1.9.1477d8bf771a9
handlebars@4.3.1
4.5.2
1
folioci/edge-caiasoft:latestc3cfa89eee2f
handlebars@4.3.1
4.5.2
1
folioci/edge-dematic:latest48c9b1d180d4
handlebars@4.3.1
4.5.2
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
handlebars@4.3.1
4.5.2
1
folioci/edge-rtac:latest15ef73b1abd0
handlebars@4.3.1
4.5.2
1
folioci/mod-calendar:latest22f65982efd7
handlebars@4.3.1
4.5.2
1
folioci/mod-data-export:latest0cc86bf09755
handlebars@4.3.1
4.5.2
1
folioci/mod-data-export-spring:latestf1d7caf4544b
handlebars@4.3.1
4.5.2
1
folioci/mod-data-export-worker:latest1ad1811c9b37
handlebars@4.3.1
4.5.2
1
folioci/mod-ebsconet:latest3ae8cb99daa3
handlebars@4.3.1
4.5.2
1
folioci/mod-inn-reach:latestcc8584e43382
handlebars@4.3.1
4.5.2
1
folioci/mod-notes:latest998ac4782e0d
handlebars@4.3.1
4.5.2
1
folioci/mod-password-validator:latestb31d75f2bf7b
handlebars@4.3.1
4.5.2
1
folioci/mod-remote-storage:latest4f12177123dc
handlebars@4.3.1
4.5.2
1
folioci/mod-tags:latest6e8beeb70272
handlebars@4.3.1
4.5.2
1
metabase/metabase:v0.53.4.17807bc5cad17
handlebars@4.3.1
4.5.2
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
handlebars@4.4.0
4.5.2
1
rodolpheche/wiremock:2.27.22328a9fce2bf
handlebars@4.2.0
4.5.2
1
strangebee/thehive:5.7.6-1e77b713124dd
handlebars@4.3.1
4.5.2
1
treskon/portrait:DEV-latest88e813f22347
handlebars@4.5.0
4.5.2
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
handlebars@4.3.1
4.5.2
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
handlebars@4.4.0
4.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.