PT-2026-44157 · Npm · Liquidjs
CVE-2026-45618
·
Published
2026-05-27
·
Updated
2026-08-11
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
liquidjs versions prior to 10.26.0
Description
LiquidJS is a template engine compatible with Shopify and GitHub Pages. A critical issue allows unauthenticated remote attackers to achieve arbitrary code execution through crafted templates. The exploit involves abusing filter evaluation, prototype manipulation, and accessing the
Function constructor. Specifically, an attacker can use the valueOf filter to gain access to the internal context and then manipulate the prototype of objects to overwrite internal methods such as this.loader.lookup and this.readFile. By controlling these components, the attacker can eventually obtain a reference to the Function constructor to execute arbitrary commands on the server.Recommendations
Update liquidjs to version 10.26.0.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liquidjs