Skip to content

fix(security): fix 4 security issues in handlebars, google-protobuf - #2538

Draft
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-PAR-901-EXSC-1199-update-packages-139419826-iitg
Draft

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-PAR-901-EXSC-1199-update-packages-139419826-iitg

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Which Linear task belongs to this PR?

🔗 Related Tasks

Why did I implement it this way?

Upgrade Handlebars and google-protobuf to fix critical RCE vulnerabilities via unsafe AST compilation and prototype pollution, XSS via unescaped script tags, and DoS via unbounded group recursion.

Checklist before requesting a review

Checklist for reviewer (DO NOT DEPLOY and contracts BEFORE CHECKING THIS!!!)

  • I have checked that any arbitrary calls to external contracts are validated and or restricted
  • I have checked that any privileged calls (i.e. storage modifications) are validated and or restricted
  • I have ensured that any new contracts have had AT A MINIMUM 1 preliminary audit conducted on by <company/auditor>

Security Impact — CVE vulnerabilities fixed by this PR

✅ 4 CVEs resolved by this upgrade, including 2 critical 🚨 CVEs

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-970464
🚨 CRITICAL
[handlebars] A vulnerability in AST validation allows arbitrary JavaScript injection through unchecked values in compile() and precompile() functions when processing untrusted ASTs, enabling remote code execution on the server or in precompiled output environments.
AIKIDO-2026-258160
🚨 CRITICAL
[handlebars] A prototype pollution vulnerability allows attackers to access the Function constructor and execute arbitrary code through templates using allowProtoMethodsByDefault: true, by exploiting the constructor property before the deny list is applied. The vulnerability enables remote code execution on the server when templates can reach prototype objects through accessible functions in the render context.
AIKIDO-2026-869467
MEDIUM
[handlebars] A vulnerability in template precompilation fails to escape </script> sequences in generated JavaScript, allowing injected script tags to execute in the browser when precompiled output is embedded inline in HTML documents. This enables arbitrary code execution for applications that precompile untrusted templates.
AIKIDO-2026-834673
HIGH
[google-protobuf] Unbounded recursion in group field skipping causes stack exhaustion when deserializing malicious protobuf messages with deeply nested groups, leading to denial of service through process crash.

@aikido-autofix
aikido-autofix Bot requested a review from a team October 10, 2026 03:03
@aikido-autofix aikido-autofix Bot added the Aikido Label created by Aikido AutoFix label Oct 10, 2026
@lifi-action-bot
lifi-action-bot marked this pull request as draft October 10, 2026 03:03
@github-actions github-actions Bot added the requires-types Trigger Types Bindings CI (ABI/type generation for lifi-contract-types) label Oct 10, 2026
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8f311206-28b7-4db5-b993-8fdd987ce053

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Aikido Label created by Aikido AutoFix AuditNotRequired requires-types Trigger Types Bindings CI (ABI/type generation for lifi-contract-types)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant