Arbitrary Code Execution Vulnerability in LiquidJS Template Engine by Harttle
CVE-2026-45618

10CRITICAL

Key Information:

Vendor

Harttle

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-45618?

LiquidJS, a popular template engine compatible with Shopify and GitHub Pages, has a vulnerability that allows the execution of arbitrary code via specially crafted templates. Users of versions prior to 10.26.0 are at risk, as this flaw permits attackers to execute harmful code within the application context. Upgrading to version 10.26.0 effectively mitigates this issue, emphasizing the importance of maintaining up-to-date software to protect against potential exploits.

Affected Version(s)

liquidjs < 10.26.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.