CVE-2026-39412: Liquidjs

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on ownPropertyOnly: true as a security boundary (e.g., multi-tenant template systems) are exposed to information disclosure of sensitive prototype properties such as API keys and tokens. This vulnerability is fixed in 10.25.4.

Affected products

  • Liquidjs Liquidjs: before 10.25.4 (fixed in 10.25.4)

Published 2026-04-08. Last modified 2026-07-24.