liquidjs
A simple, expressive, extensible Liquid template engine for JavaScript — Shopify, Jekyll and GitHub Pages compatible, for Node.js, browsers, and the CLI, with TypeScript support.
Security Advisories for liquidjs in npm
High
22 days ago
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
npm
liquidjs
High
3 months ago
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
npm
liquidjs
High
3 months ago
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
npm
liquidjs
Moderate
3 months ago
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
npm
liquidjs
Moderate
3 months ago
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
npm
liquidjs
Moderate
3 months ago
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
npm
liquidjs
High
4 months ago
liquidjs has a Denial of Service via circular block reference in layout
npm
liquidjs
Moderate
4 months ago
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
npm
liquidjs
Moderate
4 months ago
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
npm
liquidjs
High
4 months ago
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
npm
liquidjs
Low
4 months ago
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
npm
liquidjs
High
5 months ago
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
npm
liquidjs
High
5 months ago
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
npm
liquidjs