Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-45618: LiquidJS Templates Can Run Malicious Code

CVE-2026-45618 · published 23 days ago
Summary

LiquidJS templates can be used to execute arbitrary code, which means an attacker could potentially run their own code on a website or application that uses LiquidJS. This is a serious issue because it could allow an attacker to steal sensitive information, take control of the system, or cause other types of harm. To protect against this, it's recommended to update to the latest version of LiquidJS and ensure that any user-generated content is properly sanitized before being rendered with LiquidJS.

What to do
  • Update GitHub Actions liquidjs to version 10.26.0.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions liquidjs < 10.26.0
Fix: upgrade to 10.26.0
– harttle liquidjs < 10.26.0
Original advisory text
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Severity
10.0 Critical
CVSS 3.1: 10.0 (GHSA)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen27 May 2026
Sources
CVE-2026-45618 · MITRE
Monitor software like this
Free during beta