Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade liquidjs to version 10.25.3 or higher.
liquidjs is an A simple, expressive, safe and Shopify compatible template engine in pure JavaScript.
Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following through the include, render, and layout directories, when symlinks are placed within a trusted template root. An attacker can access and render files outside the intended directory by creating symlinks that point to external files.