CVE-2026-73061: Scriban

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

Affected products

  • Scriban Scriban: before 7.2.2 (fixed in 7.2.2)

Published 2026-08-16. Last modified 2026-10-08.