Liquidjs
Harttle · 18 CVEs
LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`…
Oct 6, 2026
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash…
Aug 19, 2026
LiquidJS: An infinite loop vulnerability in `strip_html` filter
Aug 19, 2026
LiquidJS is Vulnerable to Remote Code Execution
Aug 11, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
Jul 8, 2026
LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
Jun 17, 2026
LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
Jun 17, 2026
LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
Jun 17, 2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Jun 17, 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Jun 17, 2026
LiquidJS is vulnerable to Denial of Service via circular block reference in layout
May 9, 2026
LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read
Apr 8, 2026
LiquidJS has an ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sort…
Apr 8, 2026
LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates
Apr 8, 2026
LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter
Apr 8, 2026
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
Mar 26, 2026
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
Mar 26, 2026
liquidjs has a path traversal fallback vulnerability
Mar 10, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-106120 | LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration | MEDIUM | 0.35% | Oct 6, 2026 |
| CVE-2026-69222 | LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process | HIGH | 0.63% | Aug 19, 2026 |
| CVE-2026-61556 | LiquidJS: An infinite loop vulnerability in `strip_html` filter | HIGH | 0.52% | Aug 19, 2026 |
| CVE-2026-45618 | LiquidJS is Vulnerable to Remote Code Execution | CRITICAL | 0.82% | Aug 11, 2026 |
| CVE-2026-55575 | LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce | HIGH | 0.52% | Jul 8, 2026 |
| CVE-2026-45357 | LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime) | HIGH | 0.66% | Jun 17, 2026 |
| CVE-2026-44646 | LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` | MEDIUM | 0.44% | Jun 17, 2026 |
| CVE-2026-45617 | LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex | HIGH | 0.66% | Jun 17, 2026 |
| CVE-2026-44645 | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body | MEDIUM | 0.57% | Jun 17, 2026 |
| CVE-2026-44644 | LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS | MEDIUM | 0.36% | Jun 17, 2026 |
| CVE-2026-41311 | LiquidJS is vulnerable to Denial of Service via circular block reference in layout | HIGH | 0.59% | May 9, 2026 |
| CVE-2026-39859 | LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read | MEDIUM | 0.50% | Apr 8, 2026 |
| CVE-2026-39412 | LiquidJS has an ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel | HIGH | 0.47% | Apr 8, 2026 |
| CVE-2026-35525 | LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates | HIGH | 0.52% | Apr 8, 2026 |
| CVE-2026-34166 | LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter | MEDIUM | 0.57% | Apr 8, 2026 |
| CVE-2026-33285 | LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash | HIGH | 0.60% | Mar 26, 2026 |
| CVE-2026-33287 | LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern | HIGH | 0.52% | Mar 26, 2026 |
| CVE-2026-30952 | liquidjs has a path traversal fallback vulnerability | HIGH | 0.56% | Mar 10, 2026 |
Showing 1 to 18 of 18 CVEs