Scriban
NuGet8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Scribanpage 1 of 1
- CVE-2026-73061CRITICALCVSS 9.8EG 9.8✓ Fixed in 7.2.22026-08-16
vulnerable: 0.1.0 ... 7.2.1 (133 versions)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal,…
- CVE-2026-73062HIGHCVSS 7.5EG 7.5✓ Fixed in 7.2.12026-08-16
vulnerable: 3.0.0 ... 7.2.0 (78 versions)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer …
- CVE-2026-74783HIGHCVSS 7.5EG 7.5✓ Fixed in 7.2.12026-08-16
vulnerable: 6.6.0 ... 7.2.0 (10 versions)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initial…
- CVE-2026-74785MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit b…
- CVE-2026-74786MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectToString resets the per-call length counter (_currentToStringL…
- CVE-2026-74787HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger u…
- CVE-2026-74788HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating…
- CVE-2026-74792HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArra…
Check whether Scriban is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Scriban CVEs against the assets you own.
Start Free Scan →