A critical RCE vulnerability (CVE-2026-45618, CVSS 10.0) has been disclosed in LiquidJS, a Node.js Liquid template engine with over 7.3 million monthly npm downloads. The flaw stems from improper input handling in filter evaluation logic, allowing attackers to access internal JavaScript execution contexts via the valueOf filter, chain prototype manipulation to reach the Function constructor, and execute arbitrary commands — all without authentication. A public proof-of-concept exists demonstrating file reads and command execution via child_process.execSync. All LiquidJS versions prior to 10.26.0 are affected. Immediate upgrade to 10.26.0 is recommended; if patching is not possible, restrict template input from untrusted sources. Successful exploitation can lead to full host compromise, lateral movement, and data exfiltration.

3m read timeFrom orca.security
Post cover image
Table of contents
About CVE-2026-45618Affected SystemsRisk ImpactHow Orca Can Help
394 Impressions