CVE-2026-74791: Scriban

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

Affected products

  • Scriban Scriban: before 7.0.0 (fixed in 7.0.0)

Published 2026-08-16. Last modified 2026-08-31.