CVE-2026-74790: Scriban
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
Affected products
- Scriban Scriban: before 7.0.0 (fixed in 7.0.0)
Published 2026-08-16. Last modified 2026-08-31.