---
id: CVE-2026-45017
aliases:
  - GHSA-8p4x-wr7x-3788
  - PYSEC-2026-192
title: 'python-liquid: Absolute paths escape filesystem loader search path'
summary: 'python-liquid: Absolute paths escape filesystem loader search path'
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: python-liquid
product: python-liquid
ecosystem: pip
affected:
  - python-liquid < 2.2.0
patched:
  - python-liquid 2.2.0
published: '2026-05-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:51:04.993437942Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-8p4x-wr7x-3788'
references:
  - url: 'https://github.com/jg-rp/liquid/security/advisories/GHSA-8p4x-wr7x-3788'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45017'
  - url: 'https://github.com/jg-rp/liquid'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/python-liquid/PYSEC-2026-192.yaml
tags:
  - osv
  - pip
epss: 0.00336
epssPercentile: 0.27084
ingestedAt: '2026-09-12T03:13:01.678Z'
---

## Overview

### Impact
The built-in `FileSystemLoader` and `CachingFileSystemLoader` do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template authors to load and render arbitrary files via the `{% include %}` and `{% render %}` tags. Targeted files would need to contain valid Liquid markup and be readable by the application process.

### Patches
The issue is fixed in version 2.2.0 with the inclusion of a `template_path.is_absolute()` condition in `liquid/builtin/loaders/file_system_loader.py`.

```python
        if os.path.pardir in template_path.parts or template_path.is_absolute():
            raise TemplateNotFoundError(template_name)
```

### Workarounds

Create a custom template loader by inheriting from `FileSystemLoader` and overriding `resolve_path()`. Use an instance of the custom loader as the `loader` argument when instantiating your Liquid environment. 

```python
import os
from pathlib import Path

from liquid import Environment
from liquid import FileSystemLoader
from liquid.exceptions import TemplateNotFoundError


class MyFileSystemLoader(FileSystemLoader):
    def resolve_path(self, template_name: str) -> Path:
        template_path = Path(template_name)

        if self.ext and not template_path.suffix:
            template_path = template_path.with_suffix(self.ext)

        if os.path.pardir in template_path.parts or template_path.is_absolute():
            raise TemplateNotFoundError(template_name)

        for path in self.search_path:
            source_path = path.joinpath(template_path)
            if not source_path.exists():
                continue
            return source_path

        raise TemplateNotFoundError(template_name)


env = Environment(loader=MyFileSystemLoader("path/to/templates/"))
```

## Affected packages

- `python-liquid < 2.2.0`

## Remediation

Upgrade to a patched release:

- `python-liquid 2.2.0`
