{
  "@id": "urn:uuid:cf0235d8-e6d8-4c3b-92f9-5f3909ecaea9",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8861 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2015-8861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-19919 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2019-19919"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-20920 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2019-20920"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-23369 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2021-23369"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-23383 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2021-23383"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33937 affects version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2026-33937"
      },
      "action_statement": "Vulnerability CVE-2026-33937 affects version 1.3.0-tuxcare.3 of handlebars."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33938 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 CVE-2026-33938 describes a vulnerability where the @partial-block special variable can be overwritten with a crafted Handlebars AST via helpers, leading to arbitrary JavaScript execution when {{> @partial-block}} is invoked. The target repository (Handlebars 1.3.0) does not have the @partial-block feature at all, as this was introduced in later versions. The specific attack chain described in t...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33938"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33938 describes a vulnerability where the @partial-block special variable can be overwritten with a crafted Handlebars AST via helpers, leading to arbitrary JavaScript execution when {{> @partial-block}} is invoked. The target repository (Handlebars 1.3.0) does not have the @partial-block feature at all, as this was introduced in later versions. The specific attack chain described in t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33939 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by CVE-2026-33939. The vulnerability concerns decorator invocations ({{*name}} syntax), but decorators were not introduced until Handlebars 3.x+ (2015-2016), years after version 1.3.0's release in January 2014. The target codebase has no decorator support infrastructure: no DecoratorNode in the AST, no decorator visitor methods in the compiler, no decora...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33939"
      },
      "impact_statement": "not_affected \u2014 Handlebars version 1.3.0 is not affected by CVE-2026-33939. The vulnerability concerns decorator invocations ({{*name}} syntax), but decorators were not introduced until Handlebars 3.x+ (2015-2016), years after version 1.3.0's release in January 2014. The target codebase has no decorator support infrastructure: no DecoratorNode in the AST, no decorator visitor methods in the compiler, no decora..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33940 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars 1.3.0 is not affected by CVE-2026-33940. The vulnerability requires dynamic partial support ({{> (expression)}}) which was added in v3.0.0+. Version 1.3.0 additionally employs constructor validation that rejects plain JavaScript objects from being treated as AST, blocking the typical attack vector where user-controlled JSON data reaches the compiler.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33940"
      },
      "impact_statement": "not_affected \u2014 Handlebars 1.3.0 is not affected by CVE-2026-33940. The vulnerability requires dynamic partial support ({{> (expression)}}) which was added in v3.0.0+. Version 1.3.0 additionally employs constructor validation that rejects plain JavaScript objects from being treated as AST, blocking the typical attack vector where user-controlled JSON data reaches the compiler."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33941 affects version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "CVE-2026-33941"
      },
      "action_statement": "Vulnerability CVE-2026-33941 affects version 1.3.0-tuxcare.3 of handlebars."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2cf5-4w76-r9qv is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "GHSA-2cf5-4w76-r9qv"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by GHSA-442j-39wm-28r2. The vulnerability exists in the container.lookup() function when compat mode is enabled, but this function and compat mode were introduced 7.5 months after v1.3.0 was released. Version 1.3.0 uses a fundamentally different architecture for depth-based template context handling.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-442j-39wm-28r2"
      },
      "impact_statement": "not_affected \u2014 Handlebars version 1.3.0 is not affected by GHSA-442j-39wm-28r2. The vulnerability exists in the container.lookup() function when compat mode is enabled, but this function and compat mode were introduced 7.5 months after v1.3.0 was released. Version 1.3.0 uses a fundamentally different architecture for depth-based template context handling."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "GHSA-7rx3-28cr-v5wh"
      },
      "action_statement": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 1.3.0-tuxcare.3 of handlebars."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g9r4-xpmj-mj65 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "GHSA-g9r4-xpmj-mj65"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-q2c6-c6pm-g3gh is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "GHSA-q2c6-c6pm-g3gh"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/handlebars@1.3.0-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-q42p-pg8m-cqh6 is fixed in version 1.3.0-tuxcare.3 of handlebars.",
      "vulnerability": {
        "name": "GHSA-q42p-pg8m-cqh6"
      }
    }
  ]
}
