Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v273-448j-v4qj | LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liquidjs
Liquidjs liquidjs |
|
| CPEs | cpe:2.3:a:liquidjs:liquidjs:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Liquidjs
Liquidjs liquidjs |
Fri, 10 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Harttle
Harttle liquidjs |
|
| Vendors & Products |
Harttle
Harttle liquidjs |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty temporary directory as root can return the contents of arbitrary files. This vulnerability is fixed in 10.25.3. | |
| Title | LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-10T20:45:55.071Z
Reserved: 2026-04-07T19:13:20.379Z
Link: CVE-2026-39859
Updated: 2026-04-10T20:45:47.311Z
Status : Analyzed
Published: 2026-04-08T20:16:26.273
Modified: 2026-04-10T21:18:42.400
Link: CVE-2026-39859
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:27:34Z
Github GHSA