Cursor
5 exploits
Active since Feb 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
CVSS 6.1
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVSS 6.5
LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVSS 7.5
LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVSS 7.5
Open Babel <=3.1.1 - Memory Corruption
CVSS 4.3