
CVE-2026-30952 liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbitrary file access… https://www.cve.org/CVERecord?id=CVE-2026-30952
Post summary
CVE-2026-30952 exposes liquidjs templates to arbitrary file access via layout, render, and include tags in versions older than 10.25.0.

