PatchSiren

harttle CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH harttle CVE published 2026-08-19

CVE-2026-69222

The CVE-2026-69222 vulnerability affects LiquidJS, a Shopify/GitHub Pages compatible template engine in pure JavaScript. This vulnerability, present in versions prior to 10.27.2, allows for a potential crash due to incorrect complexity calculation in the join filter and concat filter. The issue arises from the computation of complexity from array.length and separator length instead of the total string len [truncated]

HIGH harttle CVE published 2026-08-19

CVE-2026-61556

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T21:17:03.633Z and has not been modified since then. The NVD entry is currently 8.7 HIGH. LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string con [truncated]

CRITICAL harttle CVE published 2026-08-11

CVE-2026-45618

CVE-2026-45618 is a critical vulnerability in LiquidJS, a Shopify/GitHub Pages compatible template engine. The issue allows for arbitrary code execution with crafted templates and was patched in version 10.26.0. This vulnerability affects LiquidJS deployments and requires immediate attention. Defenders should verify exposure and upgrade to version 10.26.0 or later. The CVSS score of 10 indicates its criti [truncated]

HIGH harttle CVE published 2026-07-08

CVE-2026-55575

CVE-2026-55575 is a high-severity vulnerability in LiquidJS, a JavaScript template engine. The pop array filter could allocate an O(N) clone of an attacker-influenced array outside the configured memoryLimit budget, potentially leading to memory exhaustion attacks. Developers and administrators using LiquidJS in their applications, especially those with high-traffic or large input data, should prioritize [truncated]

HIGH harttle CVE published 2026-06-17

CVE-2026-45357

CVE-2026-45357 is a high-severity vulnerability in LiquidJS, a Shopify/GitHub Pages compatible template engine. The vulnerability allows for memory and render limit bypass, potentially leading to large memory allocations, high CPU usage, or OOM crashes per render. This issue was fixed in version 10.26.0. Users of LiquidJS should update to the latest version to mitigate this vulnerability. The vulnerabilit [truncated]

MEDIUM harttle CVE published 2026-06-17

CVE-2026-44646

CVE-2026-44646 is a medium-severity vulnerability in LiquidJS, a Shopify/GitHub Pages compatible template engine. The issue allows for a silent bypass of the `ownPropertyOnly` value in the `Context.spawn()` method, which is used in the `{% render %}` tag. This can lead to a leak of prototype-chain properties from inside any `{% render %}` partial. The vulnerability has been fixed in version 10.26.0. Devel [truncated]

MEDIUM harttle CVE published 2026-06-17

CVE-2026-44645

CVE-2026-44645 is a MEDIUM severity vulnerability in LiquidJS, a Shopify/GitHub Pages compatible template engine. A crafted template can bypass the renderLimit, potentially causing a denial-of-service (DoS) attack. The vulnerability affects LiquidJS versions 10.25.7 and below, and the renderLimit option can be bypassed by a {% for %} or {% tablerow %} tag with an empty body. This allows a low-privileged t [truncated]

MEDIUM harttle CVE published 2026-06-17

CVE-2026-44644

CVE-2026-44644 is a medium severity XSS vulnerability in LiquidJS, a Shopify/GitHub Pages compatible template engine. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the strip_html filter logic. This issue allows attackers to bypass sanitization by placing newlines inside HTML tags, potentially leading to code execution. Developers should review and update their deployments to version 1 [truncated]

HIGH harttle CVE published 2026-05-09

CVE-2026-41311

CVE-2026-41311 is a denial-of-service vulnerability in LiquidJS. A circular {% layout %}/{% block %} reference can trigger an infinite recursive loop, consuming available memory and crashing the Node.js process. The issue is fixed in LiquidJS 10.25.7, and teams that accept untrusted Liquid templates should prioritize upgrading and adding template validation controls.