Vulnerabilities/

LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting sid

Severity:
Medium

Description

The sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on ownPropertyOnly: true as a security boundary (e.g.

Recommendation

Update the liquidjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
liquidjs
Anything's wrong? Let us know Last updated on April 09, 2026