天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-103088 Handlebars.java 目录遍历漏洞

影响攻击者可读取模板目录之外的任意文件

AI 研判

Handlebars.java 4.5.5 之前版本存在目录遍历漏洞,涉及 handlebars-springmvc 4.5.3 和 4.5.4。该组件针对 CVE-2026-63490 的路径包含修复以原始百分号编码字符串校验模板位置,而实际打开模板文件时 URL 处理器会先进行百分号解码,导致校验被绕过。

影响范围

Handlebars.java

Handlebars.java 4.5.5 之前的版本,其中 handlebars-springmvc 4.5.3 和 4.5.4 明确受影响。

漏洞详情

漏洞类型为路径遍历(目录遍历)。成因是路径包含校验与文件打开环节对百分号编码的处理不一致:校验看到的是未解码的 %2e%2e/,而文件系统打开时解码为 ../。在 Spring MVC 应用使用 file: 模板前缀且视图名来自请求时,攻击者构造含 %2e%2e/ 的请求即可绕过视图解析器与加载器的双重限制,读取模板基础目录之外的文件。

利用条件与风险

利用前提是应用使用 handlebars-springmvc 且配置 file: 模板前缀、视图名可由请求控制。实战中可导致敏感文件泄露,CVSS 7.5 属高危。

修复建议

升级 Handlebars.java 至 4.5.5 或更高版本。临时缓解措施包括避免使用 file: 模板前缀、限制视图名由请求直接派生,或对模板路径进行统一解码后再校验,暂无其他公开信息。

原始情报

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.