PT-2026-44157 · Npm · Liquidjs

Published

2026-05-27

·

Updated

2026-05-28

·

CVE-2026-45618

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liquidjs versions prior to 10.26.0
Description An issue allows unauthenticated attackers to achieve remote code execution and server compromise through crafted templates. The flaw is triggered by abusing filter evaluation, prototype manipulation, and access to the Function constructor. Specifically, using 1|valueOf during filter evaluation can return this, providing access to the internal context. Attackers can then overwrite this.loader.lookup and this.readFile to control the input of the parse() function. By manipulating the prototype and obtaining a reference to the Function constructor, arbitrary commands can be executed on the server.
Recommendations Upgrade to version 10.26.0.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45618
GHSA-GF2Q-C269-PQGC

Affected Products

Liquidjs