Report: CVE-2026-39859 - LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbit

Report: CVE-2026-39859 - LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbit

CVE ID :CVE-2026-39859 Published : April 8, 2026, 8:16 p.m. | 18 minutes ago Description :LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty temporary directory as root can return the contents of arbitrary files. This vulnerability is fixed in 10.25.3. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 8, 2026
Affected Product: GitHub