PT-2026-106841 · Npm · Liquidjs

CVE-2026-106120

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LiquidJS versions prior to 10.27.2
Description When the ownPropertyOnly setting is enabled, the engine fails to consistently restrict inherited array indices. This occurs because negative indexing, .first, .last, the first filter, the last filter, join, reverse, slice, compact, and for-loop iteration can access prototype-provided elements by bypassing the readJSProperty() function. An attacker capable of influencing the prototype state or inherited array-index data can cause templates to render these operations and disclose values that ownPropertyOnly is intended to hide.
Recommendations Update LiquidJS to version 10.27.2.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106120
GHSA-FWXR-J5W2-587M

Affected Products

Liquidjs