logo

Liquidjs CVSS 10 RCE Threatens 7.3M Monthly Users

ID: 0847e77e-9cfb-53a1-99b3-a555146ccc36

STIX ID: report--0847e77e-9cfb-53a1-99b3-a555146ccc36

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

Critical remote code execution (CVE-2026-45618) in the Liquidjs template engine enables attackers to abuse a filter evaluation flaw (valueOf) to obtain the Function constructor and run arbitrary system commands, potentially achieving full system takeover; affects Liquidjs <=10.25.7 and is patched in 10.27.0 — update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.