CVE-2026-73061: Scriban
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
Affected products
- Scriban Scriban: before 7.2.2 (fixed in 7.2.2)
Published 2026-08-16. Last modified 2026-10-08.