Vulnerability record · CVE-2026-33287 · published 26 March 2026
CVE-2026-33287: Liquidjs improper input validation vulnerability
Liquidjs · Liquidjs
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.prototype.replace()` which interprets `$&` as a back reference to the matched substring. The filter only charges `memoryLimit` for the input string length, not the amplified output. An attacker can achieve exponential memory amplification (up to 625,000:1) while staying within the `memoryLimit` budget, leading to denial of service. Version 10.25.1 patches the issue.
Description
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.prototype.replace()` which interprets `$&` as a back reference to the matched substring. The filter only charges `memoryLimit` for the input string length, not the amplified output. An attacker can achieve exponential memory amplification (up to 625,000:1) while staying within the `memoryLimit` budget, leading to denial of service. Version 10.25.1 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/harttle/liquidjs/commit/35d523026345d80458df24c72e653db78b5d061d | Patch |
| https://github.com/harttle/liquidjs/security/advisories/GHSA-6q5m-63h6-5x4v | ExploitVendor Advisory |
| https://github.com/harttle/liquidjs/security/advisories/GHSA-6q5m-63h6-5x4v | ExploitVendor Advisory |
Track CVE-2026-33287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-33287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.