CVE-2026-45618
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/harttle/liquidjs/releases/tag/v10.26.0, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45618.json, https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc, https://nvd.nist.gov/vuln/detail/CVE-2026-45618