Threat Advisory

liquidjs Flaw Discloses Inherited Array Indices

Threat: Vulnerability
Targeted Region: Global
Threat Actor Region: NA
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-106120 is a medium-severity vulnerability in LiquidJS with a CVSS score of 6.0 that discloses inherited array indices through various access paths when the ownPropertyOnly option is enabled. This allows an attacker to influence prototype state or inherited array-index data and cause templates to disclose values that the option is expected to hide. The flaw is classified as CWE-200 information disclosure and can be exploited through negative indexing, for-loop iteration, array filters and inherited array-index reads. The business impact includes potential information disclosure when applications rely on this option to safely render templates over untrusted or prototype-polluted scope data.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-106120 is a medium-severity vulnerability in LiquidJS with a CVSS score of 6.0 that discloses inherited array indices through various access paths when the ownPropertyOnly option is enabled. This allows an attacker to influence prototype state or inherited array-index data and cause templates to disclose values that the option is expected to hide. The flaw is classified as CWE-200 information disclosure and can be exploited through negative indexing, for-loop iteration, array filters and inherited array-index reads. The business impact includes potential information disclosure when applications rely on this option to safely render templates over untrusted or prototype-polluted scope data.[emaillocker id="1283"]

 

RECOMMENDATIONS:

  • We recommend you to update liquidjs to version 10.30.0 or later.

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-fwxr-j5w2-587m

[/emaillocker]
crossmenu