Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-45618Remote Code Execution in LiquidJS

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

View on NVD

Analysis

LiquidJS permite la ejecución de código arbitrario mediante el uso de plantillas maliciosas en versiones anteriores a la 10.26.0. Un atacante puede tomar control del servidor o del entorno de ejecución si logra inyectar contenido en el motor de renderizado. Es fundamental actualizar a la última versión para proteger aplicaciones web que utilicen este motor de plantillas.

Relevant roles

JavascriptTypescriptBackendFrontendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-94

EPSS

Probability of exploitation (next 30 days): 0.0085 (0.8%)
Percentile: 54.8%
EPSS: 2026-08-13

Technical description

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

Published: 8/11/2026, 8:17:40 PM
Last modified: 8/13/2026, 3:19:40 PM

References

HomeEventsBlogResourcesCoursesTeam