scriban是scriban组织的一款高性能的文本模板引擎。 scriban 6.6.0之前版本存在资源管理错误漏洞,该漏洞源于对象渲染存在无限递归,当ObjectRecursionLimit属性默认为无限制时,攻击者可向模板上下文提供循环引用对象,导致堆栈空间耗尽并触发不可捕获的StackOverflowException,从而使宿主进程终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73061 | 9.8 CRITICAL | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor |
| CVE-2026-74790 | 9.1 CRITICAL | Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache |
| CVE-2026-74784 | 8.7 HIGH | Scriban before 7.2.0 Denial of Service via array.insert_at |
| CVE-2026-74791 | 8.6 HIGH | Scriban before 7.0.0 Authorization Bypass via Stale Include Cache |
| CVE-2026-74792 | 7.5 HIGH | Scriban before 7.0.0 Stack Overflow via nested array initializers |
| CVE-2026-74783 | 7.5 HIGH | Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service |
| CVE-2026-74788 | 7.5 HIGH | Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right |
| CVE-2026-74795 | 7.5 HIGH | Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion |
| CVE-2026-74787 | 7.5 HIGH | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json |
| CVE-2026-74789 | 7.5 HIGH | Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations |
| CVE-2026-73062 | 7.5 HIGH | Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication |
| CVE-2026-73060 | 7.5 HIGH | Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply |
| CVE-2026-74785 | 6.5 MEDIUM | Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption |
| CVE-2026-74786 | 6.5 MEDIUM | Scriban before 7.0.0 Denial of Service via Unbounded Template Output |
No comments yet