A critical remote code execution vulnerability, tracked as CVE-2026-45618, was disclosed in the LiquidJS template engine from harttle. The flaw affects versions earlier than 10.26.0 and allows arbitrary code execution through crafted templates, with a CVSS 3.1 score reflecting network-exploitable impact without privileges or user interaction. The issue is classified as CWE-94, indicating improper control of code generation that can lead to command execution.
Harttle addressed the issue in LiquidJS v10.26.0 by blocking Object.prototype filter and tag lookups, the behavior identified as enabling the RCE condition. The same release also rewrote strip_html as a linear single-pass scan to reduce ReDoS risk and included additional bug fixes and new sha256 and hmac_sha256 filters. Organizations using LiquidJS should upgrade to 10.26.0 or later to remediate the vulnerability.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 11, 2026, GitHub advisory and release references were published for CVE-2026-45618, including the GHSA-gf2q-c269-pqgc advisory and the LiquidJS v10.26.0 fix reference. The disclosure tied the critical RCE issue to LiquidJS versions before 10.26.0.
A new CVE record for CVE-2026-45618 was received by security-advisories@github.com on August 11, 2026. The vulnerability affects LiquidJS versions earlier than 10.26.0 and allows arbitrary code execution through crafted templates.
Harttle released LiquidJS version 10.26.0 on 2026-05-14. The release notes state it blocks Object.prototype filter and tag lookups to prevent remote code execution, alongside other fixes and features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.