Impact
This vulnerability allows developers running LiquidJS with the ownPropertyOnly option enabled to read inherited array index values that should be excluded. By manipulating the prototype chain or providing array objects that contain prototype properties, an attacker can cause template rendering to disclose sensitive data stored on prototypes. The weakness is an information‑exposure flaw (CWE‑200) that permits disclosure of values that are intended to remain hidden.
Affected Systems
Affected hosts are those relying on the LiquidJS template engine distributed by harttle. Any use of LiquidJS older than the v10.27.2 release is vulnerable, as all releases before this version lack the proper restrictions. The fix is included in the 10.27.2 tag and later. All deployments of LiquidJS used for rendering templates that may incorporate untrusted data should verify their version against the advisory.
Risk and Exploitability
The CVSS score is 6, indicating a moderate severity. The EPSS score is not available, but the vulnerability is not currently listed in CISA KEV. Exploitation requires the ability to control object prototypes or inject malicious data into templates, which is common in web applications that render user input. The risk is moderate and may be mitigated by upgrading or by restricting the prototype chain before rendering.
OpenCVE Enrichment