Description
The layout, render, and include tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require dynamicPartials: true, which is the default).
Recommendation
Update the liquidjs package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.25.0
- Patched version(s): 10.25.0
References
Could your website be exposed too?
SmartScanner can check your website for liquidjs has a path traversal fallback vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
- Velocity.js has a Prototype Pollution vulnerability through #set path assignment - CVE-2026-44966
- electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling - CVE-2026-49253


