CyberRota Analysis
AI-GeneratedThe vulnerability in Handlebars.java allows for directory traversal, enabling attackers to access files outside the designated template base directory in Spring MVC applications. This occurs due to improper validation of template locations, where percent-encoded traversal sequences can bypass security checks. Organizations using affected versions of Handlebars.java and Spring MVC should prioritize patching to mitigate the risk of unauthorized file access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.