Skip to content

fix: pin handlebars to >=4.7.9 to resolve CVE-2026-33937#10136

Open
ssyms wants to merge 1 commit intomainfrom
fix/CVE-2026-33937-handlebars
Open

fix: pin handlebars to >=4.7.9 to resolve CVE-2026-33937#10136
ssyms wants to merge 1 commit intomainfrom
fix/CVE-2026-33937-handlebars

Conversation

@ssyms
Copy link
Copy Markdown

@ssyms ssyms commented Apr 4, 2026

Summary

Fixes CVE-2026-33937 in handlebars affecting circleci/circleci-docs.

Details

Field Value
CVE CVE-2026-33937
Affected package handlebars
Severity CRITICAL
Wiz posture issue https://app.wiz.io/issues#~(issue~'b55d2fda-7eaf-4d57-8e34-f8f2c674eaaa)

Changes made

handlebars is a transitive dependency of @antora/page-composer, @redocly/cli, and antora-shiki-extension. Added an npm overrides entry to pin handlebars to >=4.7.9, upgrading it from 4.7.8 to 4.7.9, and regenerated the lockfile.

@ssyms ssyms requested review from a team as code owners April 4, 2026 03:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant