AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106120.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Summary LiquidJS’s `ownPropertyOnly` option is intended to prevent templates from reading inherited or prototype properties from scope data. With `ownPropertyOnly: true`, direct access such as: ```liquid {{ a[0] }} ``` correctly blocks an inherited array index. However, the same inherited value is still disclosed through: ```text .first .last negative indexing for-loop iteration first last join reverse slice compact ``` ## Impact This is an information disclosure issue when an application relies on `ownPropertyOnly: true` to safely render templates over untrusted or prototype-polluted scope data. Object prototype property reads are blocked as expected, but inherited `Array.prototype` index reads are not consistently blocked. An attacker who can influence prototype state or inherited array-index data may cause templates to disclose values that `ownPropertyOnly` is expected to hide. ## Proof of concept ```js const { Liquid } = require("liquidjs"); const engine = new Liquid({ ownPropertyOnly: true }); Array.prototype[0] = "ARRAY_PROTO_POLLUTED"; Object.prototype.secret = "OBJECT_PROTO_POLLUTED"; const a = []; a.length = 1; const o = {}; for (const [src, scope] of [ ["{{ a[0] }}", {

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-fwxr-j5w2-587m

Open original source · Updated Oct 07, 2026

LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration

Source severity: MEDIUM / 6

EcosystemPackageAffected rangeFirst patched
npmliquidjs10.27.2

Original records & references

PUBLISHED 2026-10-07T12:19:09-04:00
MODIFIED 2026-10-07T12:19:10-04:00
INGESTED 2026-10-08T12:05:11-04:00