Liquidjs

Harttle · 18 CVEs

CVE-2026-106120
MEDIUM

LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`…

Oct 6, 2026

CVE-2026-69222
HIGH

LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash…

Aug 19, 2026

CVE-2026-61556
HIGH

LiquidJS: An infinite loop vulnerability in `strip_html` filter

Aug 19, 2026

CVE-2026-45618
CRITICAL

LiquidJS is Vulnerable to Remote Code Execution

Aug 11, 2026

CVE-2026-55575
HIGH

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

Jul 8, 2026

CVE-2026-45357
HIGH

LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)

Jun 17, 2026

CVE-2026-44646
MEDIUM

LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

Jun 17, 2026

CVE-2026-45617
HIGH

LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

Jun 17, 2026

CVE-2026-44645
MEDIUM

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

Jun 17, 2026

CVE-2026-44644
MEDIUM

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

Jun 17, 2026

CVE-2026-41311
HIGH

LiquidJS is vulnerable to Denial of Service via circular block reference in layout

May 9, 2026

CVE-2026-39859
MEDIUM

LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read

Apr 8, 2026

CVE-2026-39412
HIGH

LiquidJS has an ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sort…

Apr 8, 2026

CVE-2026-35525
HIGH

LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates

Apr 8, 2026

CVE-2026-34166
MEDIUM

LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter

Apr 8, 2026

CVE-2026-33285
HIGH

LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

Mar 26, 2026

CVE-2026-33287
HIGH

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

Mar 26, 2026

CVE-2026-30952
HIGH

liquidjs has a path traversal fallback vulnerability

Mar 10, 2026

Showing 1 to 18 of 18 CVEs