CVE-2026-39412 is a prototype pollution information disclosure vulnerability affecting LiquidJS, a Shopify and GitHub Pages compatible template engine, in versions prior to 10.25.4. The sort_natural filter bypasses the ownPropertyOnly security configuration, enabling template authors to extract sensitive values from prototype-inherited properties through a sorting side-channel attack. Multi-tenant template systems relying on this security boundary are particularly vulnerable to exposure of sensitive data such as API keys and tokens. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network attack vector, low complexity, requiring no privileges or user interaction. The attack has high confidentiality impact but no integrity or availability consequences, making it primarily an information disclosure risk. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog. However, the Active Hot List status and community attention indicate this should be prioritized for patching, particularly in multi-tenant environments where template isolation is a security requirement. Organizations running LiquidJS should upgrade to version 10.25.4 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.25.4CPE matchmatch criteria | cpe:2.3:a:liquidjs:liquidjs:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.