CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-45618Remote Code Execution in LiquidJS
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
View on NVDAnalysis
LiquidJS permite la ejecución de código arbitrario mediante el uso de plantillas maliciosas en versiones anteriores a la 10.26.0. Un atacante puede tomar control del servidor o del entorno de ejecución si logra inyectar contenido en el motor de renderizado. Es fundamental actualizar a la última versión para proteger aplicaciones web que utilicen este motor de plantillas.
Relevant roles
JavascriptTypescriptBackendFrontendCyberSecurity
Severity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-94EPSS
Probability of exploitation (next 30 days): 0.0085 (0.8%)
Percentile: 54.8%
EPSS: 2026-08-13
Technical description
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Published: 8/11/2026, 8:17:40 PM
Last modified: 8/13/2026, 3:19:40 PM