CVE-2026-74791
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-226
- Published
- 2026-08-16
- Last modified
- 2026-08-17
Affected products
- scriban scriban
- scriban scriban
Weakness type
Related vulnerabilities
- CVE-2026-18023 — Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a...
- CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning...
- CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
- CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not...
- CVE-2026-48984 — pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
- CVE-2026-32960 — SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive...
- CVE-2026-5795 — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two...
- CVE-2025-14858 — Semtech LR11xx Encrypted Firmware Disclosure