CRITICAL 10.0 NVD
CVE-2026-45618
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Versio
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
References
- https://github.com/harttle/liquidjs/releases/tag/v10.26.0
- https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-08-11 via NVD.
Risk Timeline
CVE Disclosed2026-08-11 · -1 days ago
Remediation Resources
vulnfeed aggregates 10022 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.