Junglewise Threat Intelligence

CVE-2026-44644: LiquidJS XSS bypass in strip_html filter

CVE-2026-44644 · Severity: medium · CVSS 6.1 · Published 2026-06-17

Technologies: liquidjs (npm). Vendors: npm.

Executive brief

LiquidJS is a popular server-side template engine used in millions of Node.js applications to safely render user content. The strip_html filter, designed to remove HTML tags and prevent XSS attacks, fails when HTML tags contain newline characters—allowing attackers to inject malicious JavaScript that bypasses sanitization entirely. Any application using strip_html to sanitize untrusted user input is vulnerable to stored or reflected cross-site scripting attacks that could steal sessions, compromise accounts, or perform unauthorized actions on behalf of victims.

Technical details

LiquidJS's strip_html filter (src/filters/html.ts) uses a regex with four alternations to remove HTML tags, comments, and script/style blocks. The vulnerable catch-all branch uses <.*?> with the . metacharacter, which does not match line terminators (\n, \r) in JavaScript without the dotAll flag. The other three branches correctly use [\s\S] to match across newlines, but the catch-all was missed. An attacker can craft a payload like <img\nsrc=x\nonerror=alert(1)> where the newline breaks the regex match, leaving the tag unescaped. Browsers parse HTML attributes with whitespace tolerance per the HTML spec and execute the onerror handler. Since liquidjs does not auto-escape filter output by default (outputEscape option is undefined), the malicious tag passes through to the HTML response unmodified. Attack requires user control over rendered input and no separate HTML escaping by the application (the default configuration). A fix is available: replace <.*?> with <[\s\S]*?> or apply the /s flag to match newlines in all branches.

Affected products

  • harttle liquidjs <= 10.25.7

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: patched: Patch commit 26ea2856c7a90aec892b98d94a9b7a3e18539045 available; v10.26.0 or later contains fix

References

Related threats