EXECUTIVE SUMMARY:
CVE-2026-106120 is a medium-severity vulnerability in LiquidJS with a CVSS score of 6.0 that discloses inherited array indices through various access paths when the ownPropertyOnly option is enabled. This allows an attacker to influence prototype state or inherited array-index data and cause templates to disclose values that the option is expected to hide. The flaw is classified as CWE-200 information disclosure and can be exploited through negative indexing, for-loop iteration, array filters and inherited array-index reads. The business impact includes potential information disclosure when applications rely on this option to safely render templates over untrusted or prototype-polluted scope data.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-106120 is a medium-severity vulnerability in LiquidJS with a CVSS score of 6.0 that discloses inherited array indices through various access paths when the ownPropertyOnly option is enabled. This allows an attacker to influence prototype state or inherited array-index data and cause templates to disclose values that the option is expected to hide. The flaw is classified as CWE-200 information disclosure and can be exploited through negative indexing, for-loop iteration, array filters and inherited array-index reads. The business impact includes potential information disclosure when applications rely on this option to safely render templates over untrusted or prototype-polluted scope data.[emaillocker id="1283"]
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-fwxr-j5w2-587m