Disclosure summary
## Summary LiquidJS’s `ownPropertyOnly` option is intended to prevent templates from reading inherited or prototype properties from scope data. With `ownPropertyOnly: true`, direct access such as: ```liquid {{ a[0] }} ``` correctly blocks an inherited array index. However, the same inherited value is still disclosed through: ```text .first .last negative indexing for-loop iteration first last join reverse slice compact ``` ## Impact This is an information disclosure issue when an application relies on `ownPropertyOnly: true` to safely render templates over untrusted or prototype-polluted scope data. Object prototype property reads are blocked as expected, but inherited `Array.prototype` index reads are not consistently blocked. An attacker who can influence prototype state or inherited array-index data may cause templates to disclose values that `ownPropertyOnly` is expected to hide. ## Proof of concept ```js const { Liquid } = require("liquidjs"); const engine = new Liquid({ ownPropertyOnly: true }); Array.prototype[0] = "ARRAY_PROTO_POLLUTED"; Object.prototype.secret = "OBJECT_PROTO_POLLUTED"; const a = []; a.length = 1; const o = {}; for (const [src, scope] of [ ["{{ a[0] }}", {
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-fwxr-j5w2-587m
Open original source · Updated Oct 07, 2026
LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration
Source severity: MEDIUM / 6
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | liquidjs | 10.27.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:19:09-04:00
MODIFIED 2026-10-07T12:19:10-04:00
INGESTED 2026-10-08T12:05:11-04:00