Answer in brief
CVE-2026-106120 records a Medium severity (CVSS 6.0) vulnerability in LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iteration. The current sources do not mark it as known exploited. The current feed maps harttle/liquidjs (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps harttle/liquidjs (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| harttle/liquidjsgeneric | <10.27.2 | 10.27.2 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, enabling ownPropertyOnly does not consistently restrict inherited array indices because negative indexing, .first, .last, the first filter, the last filter, join, reverse, slice, compact, and for-loop iteration can read prototype-provided elements outside readJSProperty(). An attacker who can influence prototype state or inherited array-index data and cause templates to render affected operations can disclose values that ownPropertyOnly is expected to hide. Direct positive indexing and ordinary object prototype reads are blocked, but the alternate array paths remain affected. This issue is fixed in 10.27.2.
Quoted source text, attributed separately from HOL analysis.