Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-45618: LiquidJS Templates Can Run Malicious Code
CVE-2026-45618 · published 23 days ago
Summary
LiquidJS templates can be used to execute arbitrary code, which means an attacker could potentially run their own code on a website or application that uses LiquidJS. This is a serious issue because it could allow an attacker to steal sensitive information, take control of the system, or cause other types of harm. To protect against this, it's recommended to update to the latest version of LiquidJS and ensure that any user-generated content is properly sanitized before being rendered with LiquidJS.
What to do
- Update GitHub Actions liquidjs to version 10.26.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | liquidjs |
< 10.26.0 Fix: upgrade to 10.26.0
|
| – | harttle | liquidjs | < 10.26.0 |
Original advisory text
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Severity
10.0
Critical
CVSS 3.1: 10.0 (GHSA)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen27 May 2026
Monitor software like this
Free during beta