CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 20:17

Updated : 2026-09-16 13:42


NVD link : CVE-2026-45618

Mitre link : CVE-2026-45618

CVE.ORG link : CVE-2026-45618


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')