Critical severity10.0GHSA Advisory· Published Aug 11, 2026· Updated Aug 13, 2026
CVE-2026-45618
CVE-2026-45618
Description
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
liquidjsnpm | < 10.26.0 | 10.26.0 |
Affected products
3- osv-coords2 versions
< 9.4.2-r1+ 1 more
- (no CPE)range: < 9.4.2-r1
- (no CPE)range: < 9.4.2-r1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.