LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Modified: 5/27/2026
package
pkg:npm/liquidjs
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Modified: 5/27/2026
liquidjs may leak properties of a prototype
Modified: 4/14/2025
liquidjs has a Denial of Service via circular block reference in layout
Modified: 5/13/2026
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
Modified: 4/10/2026
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
Modified: 3/30/2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Modified: 5/27/2026
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
Modified: 3/30/2026
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
Modified: 5/27/2026
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
Modified: 4/10/2026
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
Modified: 4/10/2026
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
Modified: 4/10/2026
liquidjs has a path traversal fallback vulnerability
Modified: 3/17/2026