liquidjs
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting liquidjspage 1 of 1
- CVE-2022-25948MEDIUMCVSS 5.3EG 5.3✓ Fixed in 10.0.02022-12-22
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable t…
- CVE-2026-34166LOWCVSS 3.7EG 3.7✓ Fixed in 10.25.32026-04-08
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + patt…
- CVE-2026-35525HIGHCVSS 7.5EG 7.5✓ Fixed in 10.25.32026-04-08
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layout…
- CVE-2026-39412MEDIUMCVSS 5.3EG 5.3✓ Fixed in 10.25.42026-04-08
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited …
- CVE-2026-39859HIGHCVSS 7.5EG 7.5✓ Fixed in 10.25.52026-04-08
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce…
- CVE-2026-41311HIGHCVSS 7.5EG 7.5✓ Fixed in 10.25.72026-05-09
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an infinite recursive loop, consuming all available memory (~4GB)…
Check whether liquidjs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for liquidjs CVEs against the assets you own.
Start Free Scan →