18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether liquidjs is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 10.0
CVE-2026-45618
LiquidJS is Vulnerable to Remote Code Execution
MEDIUM 6.1
CVE-2026-44644
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
MEDIUM 5.3
CVE-2026-39412
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
LOW 3.7
CVE-2026-34166
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
HIGH 7.5
CVE-2026-45617
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
HIGH 7.5
CVE-2026-45357
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
MEDIUM 5.3
CVE-2026-44646
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
MEDIUM 6.5
CVE-2026-44645
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
UNKNOWN
CVE-2026-39859
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
HIGH 7.5
CVE-2026-35525
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
HIGH 7.5
CVE-2026-41311
liquidjs has a Denial of Service via circular block reference in layout
UNKNOWN
CVE-2026-30952
liquidjs has a path traversal fallback vulnerability
HIGH 7.5
CVE-2026-69222
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
UNKNOWN
CVE-2026-61556
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
UNKNOWN
CVE-2026-55575
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
HIGH 7.5
CVE-2026-33285
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
HIGH 7.5
CVE-2026-33287
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
MEDIUM 5.3
CVE-2022-25948
liquidjs may leak properties of a prototype
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes