CVE-2026-45618
Critical · CVSS 10.0- CVSS
- 10.0
- nvd
- EPSS
- 0.85%
- 55th pct
- KEV
- No
- Class
- oss containerizable
- CWE-94
Description
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Affected packages
| npm | liquidjs | 0 → 10.26.0 |
References
Status: profiled · ingested 2026-08-13T18:00:50.000Z