18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether liquidjs is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 10.0
npm

CVE-2026-45618

LiquidJS is Vulnerable to Remote Code Execution

MEDIUM 6.1
npm

CVE-2026-44644

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

MEDIUM 5.3
npm

CVE-2026-39412

LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel

LOW 3.7
npm

CVE-2026-34166

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

HIGH 7.5
npm

CVE-2026-45617

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

HIGH 7.5
npm

CVE-2026-45357

LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)

MEDIUM 5.3
npm

CVE-2026-44646

LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

MEDIUM 6.5
npm

CVE-2026-44645

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

UNKNOWN
npm

CVE-2026-39859

LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read

HIGH 7.5
npm

CVE-2026-35525

LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates

HIGH 7.5
npm

CVE-2026-41311

liquidjs has a Denial of Service via circular block reference in layout

UNKNOWN
npm

CVE-2026-30952

liquidjs has a path traversal fallback vulnerability

HIGH 7.5
npm

CVE-2026-69222

LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process

UNKNOWN
npm

CVE-2026-61556

LiquidJS has an infinite loop vulnerability in its `strip_html` filter

UNKNOWN
npm

CVE-2026-55575

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

HIGH 7.5
npm

CVE-2026-33285

LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

HIGH 7.5
npm

CVE-2026-33287

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

MEDIUM 5.3
npm

CVE-2022-25948

liquidjs may leak properties of a prototype

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes