Junglewise Threat Intelligence

CVE-2026-39859: LiquidJS path traversal in renderFile and parseFile

CVE-2026-39859 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: liquidjs (npm). Vendors: npm.

Executive brief

LiquidJS is a template engine used to generate dynamic web content, similar to those used by Shopify and GitHub Pages. A security flaw allows the software to read files from the server that should be off-limits, even when a restricted "root" folder is configured. If an application allows users to influence which template file is loaded, an attacker could steal sensitive system files or configuration data.

Technical details

A path traversal vulnerability exists in LiquidJS due to improper validation of the 'root' constraint in the renderFile() and parseFile() functions. While the engine is designed to restrict file access to a specific root directory, the top-level file loader fails to enforce this boundary for absolute paths or fallback results. Specifically, in src/fs/loader.ts, the 'enforceRoot' check is bypassed for LookupType.Root, allowing the engine to resolve and read files like /etc/hosts even when a different root is configured. An attacker who can provide input to these functions can achieve arbitrary file disclosure. The issue is fixed in version 10.25.3.

Affected products

  • harttle liquidjs < 10.25.3

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats