← Back to browse · API

CVE-2026-45618

Severity
CRITICAL
CVSS
10.0
EPSS
0.00847
Risk score
40.3
CISA KEV
No
PoC
No
Published
2026-08-11
Modified
2026-08-11
First seen
2026-08-12
Aliases
EUVD-2026-56922, GHSA-GF2Q-C269-PQGC
Products
harttle:liquidjs < 10.26.0
Sources
euvd EUVD-2026-56922
nvd CVE-2026-45618

Description

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

References