liquidjs vulnerability

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

Published 11 Aug 2026Updated 16 Sep 20263 sources
CVSS 10.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.