Arbitrary Code Execution Vulnerability in LiquidJS Template Engine by Harttle
CVE-2026-45618
10CRITICAL
What is CVE-2026-45618?
LiquidJS, a popular template engine compatible with Shopify and GitHub Pages, has a vulnerability that allows the execution of arbitrary code via specially crafted templates. Users of versions prior to 10.26.0 are at risk, as this flaw permits attackers to execute harmful code within the application context. Upgrading to version 10.26.0 effectively mitigates this issue, emphasizing the importance of maintaining up-to-date software to protect against potential exploits.
Affected Version(s)
liquidjs < 10.26.0
