Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

scriban — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in scriban, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses for the Scriban templating engine, categorized under the Common Weakness Enumeration framework. It aggregates vulnerability data related to the Scriban library, focusing on issues that impact its performance, reliability, and safe usage within software applications. The content collected here covers vulnerabilities reported from the initial public release of the product through the present day. This comprehensive timeline allows users to observe the evolution of security postures as the library matured and received various updates. By providing a historical perspective, the page helps identify recurring patterns in code defects or architectural flaws that have been addressed over time. Visitors to this resource can track the vendor’s advisory history to understand how specific issues were reported and resolved. The page also offers insights into broader weakness classes, such as injection flaws or out-of-bounds memory access, illustrating how they manifest specifically within Scriban’s parsing logic. Additionally, users can look up the product’s detailed vulnerability history to assess risk levels for different versions, aiding developers in making informed decisions about dependency management and upgrade paths. This structured overview serves as a practical reference for security engineers and maintainers seeking to mitigate risks associated with the Scriban templating library in their own projects.

Vendor: scriban

CVE ID Title CVSS Severity Published
CVE-2026-74795 Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion CWE-674 7.5 High 2026-08-16
CVE-2026-74794 Scriban before 6.6.0 Denial of Service via Infinite Recursion CWE-674 7.5 High 2026-08-16
CVE-2026-74792 Scriban before 7.0.0 Stack Overflow via nested array initializers CWE-674 7.5 High 2026-08-16
CVE-2026-74791 Scriban before 7.0.0 Authorization Bypass via Stale Include Cache CWE-226 8.6 High 2026-08-16
CVE-2026-74790 Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache CWE-693 9.1 Critical 2026-08-16
CVE-2026-74789 Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations CWE-400 7.5 High 2026-08-16
CVE-2026-74788 Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right CWE-770 7.5 High 2026-08-16
CVE-2026-74786 Scriban before 7.0.0 Denial of Service via Unbounded Template Output CWE-770 6.5 Medium 2026-08-16
CVE-2026-74787 Scriban before 7.0.0 Uncontrolled Recursion via object.to_json CWE-674 7.5 High 2026-08-16
CVE-2026-74785 Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption CWE-400 6.5 Medium 2026-08-16
CVE-2026-74784 Scriban before 7.2.0 Denial of Service via array.insert_at CWE-770 8.7 High 2026-08-16
CVE-2026-74783 Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service CWE-674 7.5 High 2026-08-16
CVE-2026-73062 Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication CWE-770 7.5 High 2026-08-16
CVE-2026-73061 Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor CWE-284 9.8 Critical 2026-08-16
CVE-2026-73060 Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply CWE-770 7.5 High 2026-08-16

All 15 known CVE vulnerabilities affecting scriban with full Chinese analysis, references, and POCs where available.