<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:48:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275476</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275476</link>
      <description>EUVD-2026-275476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275476</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30952</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30952</link>
      <description>&lt;p&gt;liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require dynamicPartials: true, which is the default). This poses a security risk when malicious users are allowed to control the template content or specify the filepath to be included as a Liquid variable. This vulnerability is fixed in 10.25.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require dynamicPartials: true, which is the default). This poses a security risk when malicious users are allowed to control the template content or specify the filepath to be included as a Liquid variable. This vulnerability is fixed in 10.25.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30952</guid>
    </item>
    <item>
      <title>GHSA-wmfp-5q7x-987x — liquidjs has a path traversal fallback vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wmfp-5q7x-987x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: liquidjs&lt;/p&gt;
&lt;p&gt;### Impact
The `layout`, `render`, and `include` tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require `dynamicPartials: true`, which is the default). This poses a security risk when malicious users are allowed to control the template content or specify the filepath to be included as a Liquid variable.&lt;/p&gt;
&lt;p&gt;### Patches
The root cause is LiquidJS allows `require.resolve()` as fallback but doesn&amp;#39;t limit the directories it can resolve to. The issue is fixed via [#855](https://github.com/harttle/liquidjs/pull/855) and published version 10.25.0 on npm.&lt;/p&gt;
&lt;p&gt;### Workarounds
#### Change the files in build time
In build time, through Shell script or Webpack `string-replace-loader`, change the file content of correxponding file (depending on your package `type`, for CommonJS it&amp;#39;s `dist/liquid.node.js`) under `dist/`,&lt;/p&gt;
&lt;p&gt;```diff
  if (fs.fallback !== undefined) {
    const filepath = fs.fallback(file)
-   if (filepath !== undefined) yield filepath
+   if (filepath !== undefined) {
+     for (const dir of dirs) {
+       if (!enforceRoot || this.contains(dir, filepath)) {
+         yield filepath
+         break
+       }
+     }
    }
  }
```&lt;/p&gt;
&lt;p&gt;#### Overriding by `fs` LiquidJS option
Adding a [`fs` option](https://liquidjs.com/api/interfaces/FS.html) to override the [default `fs` implementation](https://github.com/harttle/liquidjs/blob/1b85fdaa9c535021f7030a239a64003af26d31b5/src/fs/fs-impl.ts#L36-L40):&lt;/p&gt;
&lt;p&gt;```javascript
cons…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: liquidjs&lt;/p&gt;
&lt;p&gt;### Impact
The `layout`, `render`, and `include` tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require `dynamicPartials: true`, which is the default). This poses a security risk when malicious users are allowed to control the template content or specify the filepath to be included as a Liquid variable.&lt;/p&gt;
&lt;p&gt;### Patches
The root cause is LiquidJS allows `require.resolve()` as fallback but doesn&amp;#39;t limit the directories it can resolve to. The issue is fixed via [#855](https://github.com/harttle/liquidjs/pull/855) and published version 10.25.0 on npm.&lt;/p&gt;
&lt;p&gt;### Workarounds
#### Change the files in build time
In build time, through Shell script or Webpack `string-replace-loader`, change the file content of correxponding file (depending on your package `type`, for CommonJS it&amp;#39;s `dist/liquid.node.js`) under `dist/`,&lt;/p&gt;
&lt;p&gt;```diff
  if (fs.fallback !== undefined) {
    const filepath = fs.fallback(file)
-   if (filepath !== undefined) yield filepath
+   if (filepath !== undefined) {
+     for (const dir of dirs) {
+       if (!enforceRoot || this.contains(dir, filepath)) {
+         yield filepath
+         break
+       }
+     }
    }
  }
```&lt;/p&gt;
&lt;p&gt;#### Overriding by `fs` LiquidJS option
Adding a [`fs` option](https://liquidjs.com/api/interfaces/FS.html) to override the [default `fs` implementation](https://github.com/harttle/liquidjs/blob/1b85fdaa9c535021f7030a239a64003af26d31b5/src/fs/fs-impl.ts#L36-L40):&lt;/p&gt;
&lt;p&gt;```javascript
cons…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wmfp-5q7x-987x</guid>
    </item>
  </channel>
</rss>
