python-liquid is vulnerable to Path Traversal
75
High Risk
Filesystem loaders joined attacker-influenceable template identifiers onto configured search directories without blocking anchored absolute paths, letting POSIX path joining discard the intended root and open unintended locations while still passing the historic dot-segment guard. They also accepted non-file paths where symlink hops could aim outside the declared template tree unless operators opted into explicit symlink rejection. The patch rejects absolute template paths up front, requires ordinary files, and optionally confines symlink targets within normalized roots.
You are affected if you are using a version that falls within the vulnerable range.
python-liquid is vulnerable to Path Traversal in versions 0.0.1 - 2.1.0.
Upgrade the python-liquid library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant