PT-2026-44157 · Npm · Liquidjs

CVE-2026-45618

·

Published

2026-05-27

·

Updated

2026-08-11

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liquidjs versions prior to 10.26.0
Description LiquidJS is a template engine compatible with Shopify and GitHub Pages. A critical issue allows unauthenticated remote attackers to achieve arbitrary code execution through crafted templates. The exploit involves abusing filter evaluation, prototype manipulation, and accessing the Function constructor. Specifically, an attacker can use the valueOf filter to gain access to the internal context and then manipulate the prototype of objects to overwrite internal methods such as this.loader.lookup and this.readFile. By controlling these components, the attacker can eventually obtain a reference to the Function constructor to execute arbitrary commands on the server.
Recommendations Update liquidjs to version 10.26.0.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45618
GHSA-GF2Q-C269-PQGC

Affected Products

Liquidjs