Scriban, a widely used .NET templating engine, was disclosed as affected by more than 11 vulnerabilities across versions 3.0.0 through 7.2.5, including critical CVE-2026-73061 with a reported CVSS 9.8. The most severe flaw affects TypedObjectAccessor and lets template code bypass .NET access controls to write CLR object properties without enforcing setter visibility, allowing changes to private, internal, or init-only properties as well as mass assignment on public setters. Researchers said the issue can permanently alter live host objects after template rendering, creating a serious integrity risk and possible privilege escalation in applications that process untrusted templates.
The disclosure also described multiple denial-of-service conditions, including uncontrolled recursion leading to StackOverflowException crashes, CPU and memory exhaustion through LoopLimit bypass, and cache poisoning tied to uncleared CachedTemplates. While no active exploitation was reported, the breadth and severity of the issues prompted calls for urgent remediation. Advisories identified Scriban 7.2.2 as fixing the arbitrary property write issue, while upgrading to Scriban 7.2.6 or later was presented as the comprehensive fix for the broader set of vulnerabilities; defenders were also urged to restrict untrusted template input.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
ThreatAft reported that more than 11 vulnerabilities had been disclosed in Scriban across multiple versions, highlighting CVE-2026-73061 as the most severe with a CVSS score of 9.8. The report also stated that upgrading to Scriban 7.2.6 or later was the comprehensive remediation and noted no active exploitation at publication time.
VulnCheck published an advisory describing an access-modifier bypass in Scriban's TypedObjectAccessor affecting versions before 7.2.2. The advisory said template code could write CLR object properties without enforcing setter visibility, creating a serious integrity risk for applications embedding vulnerable Scriban versions.
Scriban version 7.2.6 fixed CVE-2026-73060 in the ScriptRange.Multiply operator, where multiplying a lazy sequence by an integer bypassed LoopLimit. The flaw could be abused to cause CPU pinning and memory exhaustion through excessive iterations.
Scriban version 7.2.2 fixed CVE-2026-74791, a cache poisoning vulnerability caused by CachedTemplates not being cleared on Reset. The issue was rated CVSS 8.6 in the disclosure.
Scriban version 7.2.2 fixed CVE-2026-73061 in TypedObjectAccessor, an access-modifier bypass that let template code write CLR object properties without setter-visibility checks. The issue enabled modification of private, internal, init-only, and public-setter properties, allowing persistent alteration of live host objects and mass assignment.
Scriban version 7.2.1 fixed CVE-2026-74783, in which ExpressionDepthLimit failed to enforce recursion limits. Attackers could exploit deeply nested template constructs to crash the host process with an uncatchable StackOverflowException.
Scriban version 7.0.0 fixed CVE-2026-74787, a denial-of-service issue in object.to_json caused by missing depth limits and circular-reference detection. Self-referencing objects could otherwise trigger unbounded recursion and a fatal StackOverflowException.
Scriban version 6.6.0 fixed CVE-2026-74795, a denial-of-service vulnerability in the recursive-descent parser caused by ExpressionDepthLimit defaulting to null or disabled. The flaw allowed deeply nested templates to trigger an uncatchable StackOverflowException and terminate the hosting .NET process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.