Skip to content

fix(deps): CVE-2026-106446 (critical) + CVE-2026-106445 (critical) — bump handlebars to 4.7.10 - #1964

Merged
mishushakov merged 1 commit into
mainfrom
devin/1791529556-handlebars-cve
Oct 9, 2026
Merged

mishushakov merged 1 commit into
mainfrom
devin/1791529556-handlebars-cve

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

pnpm audit flags handlebars@4.7.9, a direct runtime dependency of @e2b/cli. It's in published code: src/commands/template/generators/handlebars.ts calls handlebars.compile() to render the files that e2b template init / e2b template migrate generate, and tsdown bundles it into dist/index.js.

Advisory Severity Issue Fixed in
CVE-2026-106446 / GHSA-8r5x-fm3f-whwj critical JS injection via AST type confusion in compile (bypass of CVE-2026-33937) 4.7.10
CVE-2026-106445 / GHSA-p8wg-vrv2-v86f critical JS injection via own-property check bypass 4.7.10
CVE-2026-106444 / GHSA-xw65-4hp5-5hc7 moderate JS injection via unsafe inline embedding of precompiled templates 4.7.10
 # packages/cli/package.json
-    "handlebars": "^4.7.9",
+    "handlebars": "^4.7.10",

This is a patch bump (smallest version that clears all three). The two critical CVEs are in one PR because the same one-line bump fixes both, and splitting them would just produce two identical, conflicting PRs. 4.7.10 was published 2026-10-05 22:37 UTC, so it's already past the workspace's minimumReleaseAge (3 days). The lockfile diff only touches handlebars (also re-resolved under @types/handlebars). Includes a @e2b/cli patch changeset.

Verified locally: pnpm audit no longer reports handlebars. @e2b/cli typecheck and build pass, and vitest run passes (19 files / 139 tests, including the template init/migrate tests that render through Handlebars).

Link to Devin session: https://app.devin.ai/sessions/b8295685b92640839d4f6176892cc5e7
Open in Devin Desktop: https://app.devin.ai/desktop/session/b8295685b92640839d4f6176892cc5e7?variant=devin


Devin Review

…critical)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@cla-bot cla-bot Bot added the cla-signed label Oct 9, 2026
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d520c0a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@e2b/cli Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T07:10:27.731507Z d520c0a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TASTE.md review: no violations. This PR only bumps the handlebars dependency in @e2b/cli and adds a changeset; it doesn’t change any JS or Python SDK API, so T-1 to T-74 didn’t flag anything.

Written by Devin

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Package Artifacts

Built from 4e3b701. Download artifacts from this workflow run.

JS SDK (e2b@2.54.1-devin-1791529556-handlebars-cve.0, with @e2b/dockerfile-utils@0.1.1-devin-1791529556-handlebars-cve.0):

npm install ./e2b-dockerfile-utils-0.1.1-devin-1791529556-handlebars-cve.0.tgz ./e2b-2.54.1-devin-1791529556-handlebars-cve.0.tgz

CLI (@e2b/cli@2.21.2-devin-1791529556-handlebars-cve.0):

npm install ./e2b-cli-2.21.2-devin-1791529556-handlebars-cve.0.tgz

Code Interpreter JS SDK (@e2b/code-interpreter@2.8.3-devin-1791529556-handlebars-cve.0):

npm install ./e2b-code-interpreter-2.8.3-devin-1791529556-handlebars-cve.0.tgz

Desktop JS SDK (@e2b/desktop@2.4.1-devin-1791529556-handlebars-cve.0):

npm install ./e2b-desktop-2.4.1-devin-1791529556-handlebars-cve.0.tgz

Python SDK (e2b==2.54.0+devin.1791529556.handlebars.cve, with e2b-dockerfile-utils==0.1.0+devin.1791529556.handlebars.cve):

pip install ./e2b_dockerfile_utils-0.1.0+devin.1791529556.handlebars.cve-py3-none-any.whl ./e2b-2.54.0+devin.1791529556.handlebars.cve-py3-none-any.whl

Code Interpreter Python SDK (e2b-code-interpreter==2.10.3+devin.1791529556.handlebars.cve):

pip install ./e2b_code_interpreter-2.10.3+devin.1791529556.handlebars.cve-py3-none-any.whl

Desktop Python SDK (e2b-desktop==2.6.1+devin.1791529556.handlebars.cve):

pip install ./e2b_desktop-2.6.1+devin.1791529556.handlebars.cve-py3-none-any.whl

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

CI note: the only failure is Production / Python SDK - Build and test (ubuntu-22.04) → test_auto_resume_wakes_on_http_request ("sandbox did not reach paused; last state was running"). This is a live-sandbox timing test, and this PR doesn't touch the Python SDK (the lockfile diff only touches handlebars). The same suite passed on Production windows and on both Staging runners, and the test passes locally against production (1 passed in 4.06s). It looks flaky; a re-run should clear it.

Written by Devin

@mishushakov
mishushakov enabled auto-merge (squash) October 9, 2026 09:28
@mishushakov
mishushakov merged commit 001406c into main Oct 9, 2026
83 of 85 checks passed
@mishushakov
mishushakov deleted the devin/1791529556-handlebars-cve branch October 9, 2026 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant