Zurück zur CVE-Übersicht
CVE-2026-45618
CRITICAL(10.0)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Risk Signal Score25/100 — MITTEL
- CVSS 10 — Kritisch
EPSS-Score
0.8%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
10
Technische Schwere
SecBoard-Einordnung
CVE-2026-45618 betrifft LiquidJS, eine Template-Engine, die mit Shopify und GitHub Pages kompatibel ist. Die Schwachstelle ermöglicht die Ausführung von beliebigem Code durch speziell gestaltete Templates. Dies kann zu einer vollständigen Kompromittierung des Systems führen, auf dem LiquidJS ausgeführt wird.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
GitHub Advisories
GHSA-gf2q-c269-pqgcCRITICAL
LiquidJS is Vulnerable to Remote Code Execution
npm/liquidjs→ 10.26.0
GitHub Advisory