Liquidjs is a templating engine widely embedded across web applications and build pipelines as a Liquid template parser and renderer. Its durable vulnerability signal centers on resource-handling and input-validation weaknesses, including uncontrolled resource consumption, path traversal, and exposure of sensitive information, which are characteristic of template-processing and file-access logic in a library component. Current severity, exploitation status, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liquidjs over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39859HIGH LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile | Apr 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-39412HIGH LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropertyOnly security option, allowing | Apr 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-41311MEDIUM LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an inf | May 9, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-35525HIGH LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the | Apr 8, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-33287HIGH LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.proto | Mar 26, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-33285HIGH LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mechanism can be completely bypassed | Mar 26, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-30952HIGH liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbitrary file access via absolute | Mar 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-34166MEDIUM LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the | Apr 8, 2026 | 5.3 | 22 | NO | NO |
CVE-2022-25948MEDIUM The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workar | Dec 22, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liquidjs.
Media articles that mention a CVE ID that affects a product developed by Liquidjs — matched by CVE ID, not by vendor name.