NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1205 most downloaded on npm
Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
Last release 6 months ago
26 Mar 2026
Ships unpredictably
gaps range from 8 days to 2.6 years
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
81 releases · first in 2011
fix: enable shell mode for spawn to resolve Windows EINVAL issue - e0137c2
hash to be a Record<string, any> - de4414dOne column per quarter.
Make library compatible with workers ( #1894 ) - 3d3796c
That is why we only bump the patch version despite mentioning breaking changes.
(POSSIBLY) BREAKING CHANGES:
That is why we only bump the patch version despite mentioning breaking changes.
Chore/Housekeeping: - #1672 - Switch cmd parser to latest minimist (@dougwilson Compatibility notes: - Restored Node.js compatibility Commits
Chore/Housekeeping:
Compatibility notes:
~Node.js version support has been changed to v6+~ Reverted in 4.7.6
Chore/Housekeeping:
Compatibility notes:
Fix spelling and punctuation in changelog - d78cc73
Chore/Housekeeping:
Bugfixes:
Compatibility notes:
No breaking changes are to be expected
Bugfixes:
Chore/Build:
Compatibility notes:
fix: fix log output in case of illegal property access - f152dfc
Bugfixes:
Compatibility notes:
feat: default options for controlling proto access - 7af1c12, #1635
Features:
Compatibility notes:
That is why we only bump the minor version despite mentioning breaking changes.
Features:
Bugfixes:
Chores, docs:
BREAKING CHANGES:
access to prototype properties is forbidden completely by default, specific properties or methods can be allowed via runtime-options. See #1633 for details. If you are using Handlebars as documented, you should not be accessing prototype properties from your template anyway, so the changes should not be a problem for you. Only the use of undocumented features can break your build.
That is why we only bump the minor version despite mentioning breaking changes.
add chai and dirty-chai and sinon, for cleaner test-assertions and spies, deprecate old assertion-methods - 93e284e, 886ba86, 0817dad, 93516a0
Bugfixes:
Chores / Build:
Security:
__proto__, __defineGetter__, __defineSetter__ and __lookupGetter__
have been added to the list of "properties that must be enumerable".
If a property by that name is found and not enumerable on its parent,
it will silently evaluate to undefined. This is done in both the compiled template and the "lookup"-helper.
This will prevent new Remote-Code-Execution exploits that have been
published recently.Compatibility notes:
__proto__, __defineGetter__, __defineSetter__ and __lookupGetter__ in the respect that those expression now return
undefined rather than their actual value from the proto.{
__proto__: 'some string';
}
fix: use String(field) in lookup when checking for "constructor" - d541378
Compatibility notes:
fix: move "eslint-plugin-compat" to devDependencies - 5e9d17f
Bugfixs
Compatibility notes:
Resolve deprecation warning message from eslint while running eslint (#1586) - 7052e88
Features / Improvements
Bugfixes:
Chore:
Compatibility notes:
Contents of raw-blocks must be matched with non-eager regex-matching - 8d5530e, #1579
Bugfixes:
fix: prevent zero length tokens in raw-blocks (#1577, #1578) - f1752fe
Bugfixes:
Chore:
Compatibility notes:
add missing type fields to AST typings and add tests for them - 0440af2
chore: fix grunt-saucelabs dependency - b7eada0
- #1562 - Error message for syntax error missing location in 4.2.1+ Commits
Added support for iterable objects in {{#each}} helper (#1557) - cf7545e
Error message for syntax error missing location in 4.2.1+
fix: harden "propertyIsEnumerable"-check - ff4d827
Compatibility notes:
fix test case for browsers that do not support defineGetter - 8742bde
Use Object.prototype.propertyIsEnumerable to check for constructors - 213c0bb, #1563
Compatibility notes:
do not break on precompiled templates from Handlebars >=4.0.0 <4.3.0 - 1266838, #1561
Fixes:
Security: Disallow calling "helperMissing" and "blockHelperMissing" directly - 2078c72
Fixes:
Features:
allowCallsToHelperMissing to allow calling blockHelperMissing and helperMissing.Breaking changes:
Compatibility notes:
Compiler revision increased - 06b7224
Disallow calling "helperMissing" and "blockHelperMissing" directly - 2078c72
{{blockHelperMissing}} was
never intended and was part of the exploits that have been revealed early in 2019
(see https://github.com/handlebars-lang/handlebars.js/issues/1495). It is also part of a new exploit that
is not captured by the earlier fix. In order to harden Handlebars against such exploits, calling thos helpers
is now not possible anymore. Overriding those helpers is still possible.allowCallsToHelperMissing to true and the
calls will again be possibleBoth bullet points imly that Handlebars is not 100% percent compatible to 4.2.0, despite the minor version bump.
We consider it more important to resolve a major security issue than to maintain 100% compatibility.
Error message for syntax error missing location in 4.2.1+
The "browser" property in the package.json has been updated to use the common-js builds instead of the minified UMD - c55a7be, #1553
Bugfixes:
Compatibility notes:
Use custom grunt-saucelab with current sauce-connect proxy - f119497
Chore/Test:
grunt-saucelab with current sauce-connect proxy - f119497Bugfixes:
knownHelpers doesnt allow for custom helpers (@NickCis)Features:
Compatibility notes:
This kind of access is not the intended use of Handlebars and leads to the vulnerability described in #1495. We will not increase the major version, b…
Chore/Test:
Bugfixes:
Compatibility notes:
Access to the constructor of a class thought {{lookup obj "constructor" }} is now prohibited. This closes
a leak that only half closed in versions 4.0.13 and 4.1.0, but it is a slight incompatibility.
This kind of access is not the intended use of Handlebars and leads to the vulnerability described in #1495. We will not increase the major version, because such use is not intended or documented, and because of the potential impact of the issue (we fear that most people won't use a new major version and the issue may not be resolved on many systems).
Nothing published for this version
This is a bugfix release. There are no breaking change and no new features.
Bugfixes:
Refactorings:
Compatibility notes:
This kind of access is not the intended use of Handlebars and leads to the vulnerability described in #1495. We will not increase the major version, b…
New Features
Security fixes:
Housekeeping
Compatibility notes:
Access to class constructors (i.e. ({}).constructor) is now prohibited to prevent
Remote Code Execution. This means that following construct will no work anymore:
class SomeClass {
}
SomeClass.staticProperty = 'static'
var template = Handlebars.compile('{{constructor.staticProperty}}');
document.getElementById('output').innerHTML = template(new SomeClass());
// expected: 'static', but now this is empty.
This kind of access is not the intended use of Handlebars and leads to the vulnerability described in #1495. We will not increase the major version, because such use is not intended or documented, and because of the potential impact of the issue (we fear that most people won't use a new major version and the issue may not be resolved on many systems).
Nothing published for this version
Nothing published for this version
Update grunt-eslint to 20.1.0 - 7729aa9
New features:
Various dependency updates
Bugfixes:
source-map-package should work better with rollup#1463Removed obsolete code:
files field - 69c6ca5Compatibility notes:
This is a bugfix release. There are no breaking change and no new features.
uglify-js is unconditionally imported, but only listed as optional dependency (@Turbo87)Compatibility notes:
Fix regression in 4.0.9: Replace "Object.assign" (not support in IE) by "util/extend" - 0e953d1
pending #1331 Attempts to build Handlebars in a Windows environment
node handlebars -a ... on Windows - 2e21e2bCompatibility notes:
- #1341 #1342 Allow partial-blocks to be executed without "options" (@nknapp) - a00c598 Compatibility notes: - No breaking changes Commits
- #1319: Fix context-stack when calling block-helpers on null values (@nknapp) - c8f4b57 - #1315 Parser: Change suffix to use ES6 default module expor
Update jsfiddle to point to latest - 959ee55 (originally dfc7554 by @kpdecker)
Return current handlebars instance from noConflict - 685cf92
- #1121 - Include partial name in 'undefined partial' exception message (@shinypb) - #1125 - Add promised-handlebars to "in-the-wild"-list (@nknapp) C
each iteration with undefined values has been restored to the 3.0 behaviors. Helper calls with undefined context values will now execute against an ar
Compatibility notes:
each iteration with undefined values has been restored to the 3.0 behaviors. Helper calls with undefined context values will now execute against an arbitrary empty object to avoid executing against global object in non-strict mode.] can now be included in [] wrapped identifiers by escaping with \. Any [] identifiers that include \ will now have to properly escape these values.- #1089 - "Failover content" not working in multiple levels of inline partials (@michaellopez) Commits
Fix failure when using decorators in partials - 05b82a2
Escape = in HTML content - 83b8e84
Compatibility notes:
if that do not seem to alter the context. Any instances of ../ in templates will need to be checked for the correct behavior under 4.0.0. In general templates will either reduce the number of ../ instances or leave them as is. See #1028.= character is now HTML escaped. This closes a potential exploit case when using unquoted attributes, i.e. <div foo={{bar}}>. In general it's recommended that attributes always be quoted when their values are generated from a mustache to avoid any potential exploit surfaces.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- #1004 - Latest version breaks with RequireJS (global is undefined) (@boskee) Commits
Use captureStackTrace for error handler - a009a97
- #984 - Adding documentation for passing arguments into partials (@johneke) - #973 - version 3 is slower than version 2 (@elover) - #966 - "handlebar
Runtime breaking changes. Must match 3.x runtime and precompiler.
#940 - Add missing reserved words so compiler knows to use array syntax: (@mattflaschen)
#930 - Add parent tracking and mutation to AST visitors (@kpdecker)
#926 - Depthed lookups fail when program duplicator runs (@kpdecker)
#918 - Add instructions for 'spec/mustache' to CONTRIBUTING.md, fix a few typos (@oneeman)
#910 - Different behavior of {{@last}} when {{#each}} in {{#each}} (@zordius)
#907 - Implement named helper variable references (@kpdecker)
#903 - Only provide aliases for multiple use calls (@kpdecker)
#901 - Still escapes with noEscape enabled on isolated Handlebars environment (@zedknight)
#896 - Simplify BlockNode by removing intermediate MustacheNode (@mmun)
#892 - Implement parser for else chaining of helpers (@kpdecker)
#887 - Handlebars.noConflict() option? (@bradvogel)
#886 - Add SafeString to context (or use duck-typing) (@dominicbarnes)
#870 - Registering undefined partial throws exception. (@max-b)
#858 - Disable new default auto-indent at included partials (@majodev)
#856 - jspm compatibility (@MajorBreakfast)
Export the default object for handlebars/runtime - 5594416
Lookup partials when undefined - 617dd57
Compatibility notes:
JavaScriptCompiler APIs have been formalized and documented. As part of the sourcemap handling these should be updated to return arrays for concatenation.JavaScriptCompiler.namespace has been removed as it was unused.SafeString is now duck typed on toHTMLNew Features:
Update jsfiddle to 2.0.0-beta.1 - 0670f65
Changes to 0/undefined handling
#787 - Remove whitespace surrounding standalone statements (@kpdecker)
Changes to 0/undefined handling
#773 - Implicit parameters in {{#each}} introduces a peculiarity in helpers calling convention (@Bertrand)
#783 - helperMissing and consistency for different expression types (@ErisDS)
#795 - Turn the precompile script into a wrapper around a module. (@jwietelmann)
#823 - Support inverse sections on the with helper (@dan-manges)
#852 - {{foo~}} space control behavior is different from older version (@zordius)
#835 - Templates overwritten if file is loaded twice
Expose escapeExpression on the root object - 980c38c
Remove nested function eval in blockHelperMissing - 6f22ec1
Fix compiler program de-duping - 9e3f824
Compatibility notes:
programWithDepth has been removed an instead an array of context values is passed to fields needing depth lookups.false values are now printed to output rather than silently droppedAST.ProgramNode's signature has changed.JavaScriptCompiler.registerJavaScriptCompiler.replaceStack no longer supports non-inline replaceCompiler.disassembleDECLARE opcodestrip opcodelookup opcodestring values mutated over time. original field provides the unmodified value.Handlebars.registerHelper inverse parametereach helper requires iterator parameterYour coding agent can read these notes before it upgrades. Set up the MCP server →