Product
high
advisory
Authorization Bypass in Scriban via Stale Template Cache
1 TTP 1 CVEScriban versions before 7.0.0 fail to clear the CachedTemplates dictionary during TemplateContext.Reset(), potentially allowing unauthorized access to template content across reused contexts.
Scriban +2
1t
1c
critical
advisory
Access-Modifier Bypass in Scriban
3 TTPs 1 CVEScriban versions prior to 7.2.2 contain an access-modifier bypass in TypedObjectAccessor that allows unauthorized modification of private, internal, or init-only CLR object properties via template injection.
Scriban +3
vulnerability
dot-net
template-injection
access-control
sandbox-bypass
cve-2026-74790
.net
denial-of-service
+1
3t
1c