CVE-2026-45618: Harttle Liquidjs
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
Affected products
- Harttle Liquidjs: before 10.26.0 (fixed in 10.26.0)
Published 2026-08-11. Last modified 2026-09-16.