CVE-2026-35525
LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates
Description
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots before reading it. That check is path-based, not realpath-based. Because of that, a file like partials/link.liquid passes the directory containment check as long as its pathname is under the allowed root. If link.liquid is actually a symlink to a file outside the allowed root, the filesystem follows the symlink when the file is opened and LiquidJS renders the external target. So the restriction is applied to the path string that was requested, not to the file that is actually read. This matters in environments where an attacker can place templates or otherwise influence files under a trusted template root, including uploaded themes, extracted archives, mounted content, or repository-controlled template trees. This vulnerability is fixed in 10.25.3.
INFO
Published Date :
April 8, 2026, 8:16 p.m.
Last Modified :
July 24, 2026, 9:10 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 4.0 | HIGH | [email protected] |
Solution
- Update LiquidJS to version 10.25.3.
- Ensure template roots are securely configured.
- Validate all included/rendered template paths.
Public PoC/Exploit Available at Github
CVE-2026-35525 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-35525.
| URL | Resource |
|---|---|
| https://github.com/harttle/liquidjs/pull/867 | Issue Tracking |
| https://github.com/harttle/liquidjs/releases/tag/v10.25.3 | Release Notes |
| https://github.com/harttle/liquidjs/security/advisories/GHSA-56p5-8mhr-2fph | Exploit Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-35525 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-35525
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Public CVE writeups, reproducible proof-of-concepts, and reusable scanners from my vulnerability research.
cve poc scanner security writeups
Python Shell JavaScript
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-35525 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-35525 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: LiquidJS de Harttle, Description: LiquidJS es un motor de plantillas compatible con Shopify / GitHub Pages en JavaScript puro. Antes de la versión 10.25.3, para {% include %}, {% render %} y {% layout %}, LiquidJS verifica si la ruta candidata está dentro de las raíces de parciales o diseños configuradas antes de leerla. Esa verificación se basa en la ruta, no en la ruta real. Debido a eso, un archivo como partials/link.liquid pasa la verificación de contención de directorio siempre que su nombre de ruta esté bajo la raíz permitida. Si link.liquid es en realidad un enlace simbólico a un archivo fuera de la raíz permitida, el sistema de archivos sigue el enlace simbólico cuando se abre el archivo y LiquidJS renderiza el objetivo externo. Así, la restricción se aplica a la cadena de ruta que fue solicitada, no al archivo que realmente se lee. Esto importa en entornos donde un atacante puede colocar plantillas o influir de otra manera en archivos bajo una raíz de plantilla de confianza, incluyendo temas subidos, archivos extraídos, contenido montado o árboles de plantillas controlados por repositorio. Esta vulnerabilidad se corrige en la versión 10.25.3. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'harttle', 'product': 'liquidjs', 'versions': [{'status': 'affected', 'version': '< 10.25.3'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-35525', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-04-08T19:52:53.691880Z'} -
Initial Analysis by [email protected]
Apr. 10, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Added CPE Configuration OR *cpe:2.3:a:liquidjs:liquidjs:*:*:*:*:*:node.js:*:* versions up to (excluding) 10.25.3 Added Reference Type GitHub, Inc.: https://github.com/harttle/liquidjs/pull/867 Types: Issue Tracking Added Reference Type GitHub, Inc.: https://github.com/harttle/liquidjs/releases/tag/v10.25.3 Types: Release Notes Added Reference Type GitHub, Inc.: https://github.com/harttle/liquidjs/security/advisories/GHSA-56p5-8mhr-2fph Types: Exploit, Vendor Advisory -
New CVE Received by [email protected]
Apr. 08, 2026
Action Type Old Value New Value Added Description LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots before reading it. That check is path-based, not realpath-based. Because of that, a file like partials/link.liquid passes the directory containment check as long as its pathname is under the allowed root. If link.liquid is actually a symlink to a file outside the allowed root, the filesystem follows the symlink when the file is opened and LiquidJS renders the external target. So the restriction is applied to the path string that was requested, not to the file that is actually read. This matters in environments where an attacker can place templates or otherwise influence files under a trusted template root, including uploaded themes, extracted archives, mounted content, or repository-controlled template trees. This vulnerability is fixed in 10.25.3. Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-61 Added Reference https://github.com/harttle/liquidjs/pull/867 Added Reference https://github.com/harttle/liquidjs/releases/tag/v10.25.3 Added Reference https://github.com/harttle/liquidjs/security/advisories/GHSA-56p5-8mhr-2fph