Skip to main content
Echelon
Graph
Product
Enterprise
Compliance
Pulse
More Pulse pages
Exposures
AI Analyst
Compare
Radar
Book a Demo
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-33938
CVE-2026-33938
High
CVSS
8.1
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
Vendor
Microsoft Security Response Center (MSRC)
Published
May 31, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-33938 →
🎯 Affected products
1
cbl2 reaper 3.1.1-22 on CBL Mariner 2.0
🔗 References (1)
advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33938