Junglewise Threat Intelligence

CVE-2026-45618: LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with craft

CVE-2026-45618 · Severity: critical · CVSS 10 · Published 2026-08-11

Technologies: liquidjs (npm). Vendors: npm.

Executive brief

LiquidJS, a popular template engine for Node.js, is vulnerable to a critical security flaw that allows attackers to execute arbitrary code on the server. By providing a specially crafted template, an attacker can bypass security boundaries to take full control of the underlying system, potentially leading to data theft, service disruption, or further network compromise. Organizations using LiquidJS to render user-provided content should update to version 10.26.0 or later immediately.

Technical details

LiquidJS is vulnerable to Remote Code Execution (RCE) due to improper isolation during template evaluation. An attacker can use the `valueOf` filter to obtain a reference to the internal `this` context (the scope). By leveraging 'comparable' gadgets and prototype pollution techniques within the template, an attacker can overwrite internal properties such as `this.loader.lookup` and `this.readFile`. This allows the attacker to manipulate the `_parseFile` generator to obtain a reference to the `Function` constructor, enabling the execution of arbitrary JavaScript code. The vulnerability is patched in version 10.26.0.

Affected products

  • harttle liquidjs < 10.26.0

Timeline

  • 2026-05-24: disclosed
  • 2026-05-27: advisory

References

Related threats