Vulnerability Description
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/harttle/liquidjs/releases/tag/v10.26.0
- https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc
- https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc
FAQ
What is CVE-2026-45618?
CVE-2026-45618 is a vulnerability with a CVSS score of 10.0 (CRITICAL). LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
How severe is CVE-2026-45618?
CVE-2026-45618 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45618?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.