In versions prior to 4.6.0 it was possible to fabricate templates that would crash a node.js server running handlebars. Details have been disclosed (last year) at https://hackerone.com/reports/726364