Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106120— LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration

Quick assessment

Affected
harttle liquidjs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LiquidJS 是一个兼容 Shopify 和 GitHub Pages 的纯 JavaScript 模板引擎。在版本 10.27.2 之前,启用 选项并不能始终如一地限制对继承数组索引的访问,因为负数索引、 、 、 过滤器、 过滤器、 、 、 、 以及 循环迭代等操作,可能会在 外部读取到由原型链提供的元素。攻击者若能够影响原型状态或继承的数组索引数据,并促使模板渲染受影响的操作,则可能泄露原本期望被 机制隐藏的值。尽管直接的正数索引和常规的对象原型读取已被阻止,但替代性的数组访问路径仍受到影响。该问题已在版本

CVSS 6.0 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
harttle liquidjs < 10.27.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106120

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration
Source: CVE Program / CVE List V5
Vulnerability Description
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, enabling ownPropertyOnly does not consistently restrict inherited array indices because negative indexing, .first, .last, the first filter, the last filter, join, reverse, slice, compact, and for-loop iteration can read prototype-provided elements outside readJSProperty(). An attacker who can influence prototype state or inherited array-index data and cause templates to render affected operations can disclose values that ownPropertyOnly is expected to hide. Direct positive indexing and ordinary object prototype reads are blocked, but the alternate array paths remain affected. This issue is fixed in 10.27.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
harttle liquidjs < 10.27.2 -

II. Public POCs for CVE-2026-106120

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106120

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-106120 (2)

Vendor Advisories for CVE-2026-106120 (1)

Vendor Pages for CVE-2026-106120 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106120

No comments yet


Leave a comment