scriban
NuGet6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting scribanpage 1 of 1
- CVE-2026-74784HIGHCVSS 8.7EG 8.7✓ Fixed in 7.2.02026-08-16
vulnerable: 0.1.0 ... 7.1.0 (131 versions)
Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter t…
- CVE-2026-74789HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..10000…
- CVE-2026-74790CRITICALCVSS 9.1EG 9.1✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields b…
- CVE-2026-74791HIGHCVSS 8.6EG 8.6✓ Fixed in 7.0.02026-08-16
vulnerable: 0.1.0 ... 6.6.0 (123 versions)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations…
- CVE-2026-74794HIGHCVSS 7.5EG 7.5✓ Fixed in 6.6.02026-08-16
vulnerable: 0.1.0 ... 6.5.8 (122 versions)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack s…
- CVE-2026-74795HIGHCVSS 7.5EG 7.5✓ Fixed in 6.6.02026-08-16
vulnerable: 0.1.0 ... 6.5.8 (122 versions)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabl…
Check whether scriban is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for scriban CVEs against the assets you own.
Start Free Scan →