← العودة للجدول
CVE-2026-45618
CVE-2026-45618 — GHSA: LiquidJS is Vulnerable to Remote Code Execution
📅 2026-05-27
🔴 Critical 🔥 PoC Only GHSA PoC Research General CVSS 10

📋 الوصف الكامل

### Summary It is possible to execute arbitrary code with crafted templates ### Details `1|valueOf` -> `this` when evaluating the filter ```liquid {%assign r=1|valueOf%} {{r|inspect}} ``` ```json {"context":{"scopes":[{"r":"[Circular]"}],"registers":{},"breakCalled":false,"continueCalled":false,"sync":fal

💻 الأنظمة المتأثرة

Multiple Systems

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-45618

📡 المصدر

GHSA

✅ الحلول والتخفيف

Refer to CVE-2026-45618 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←