THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g29j-rwfv-h99w (high) — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

[GHSA] GHSA-g29j-rwfv-h99w (high) — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

highgithub_advisoriesPublished 2026-09-02

GHSA-g29j-rwfv-h99w Severity: high CVE: CVE-2026-63490

Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

### Summary `com.github.jknack.handlebars.springmvc.SpringTemplateLoader` resolves Spring MVC view names into URLs via Spring's `ResourceLoader` **without applying the path-containment check** that protects every other URL-based loader in the projec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g29j-rwfv-h99w