Junglewise Threat Intelligence

CVE-2026-74791: Scriban authorization bypass via stale include cache

CVE-2026-74791 · Severity: high · CVSS 8.6 · Published 2026-08-16

Technologies: Scriban, Scriban.Signed (NuGet). Vendors: NuGet.

Executive brief

Scriban is a templating engine used by applications to render dynamic content. When applications reuse and reset template contexts (a performance optimization), Scriban fails to clear cached templates, allowing an attacker to access previously rendered authorized content meant for a different request or user. This could lead to exposure of sensitive data across multiple renders.

Technical details

The vulnerability is a sensitive information exposure issue (CWE-226) in Scriban's template caching mechanism. When TemplateContext.Reset() is called to safely reuse a context object, the CachedTemplates dictionary is not cleared. Subsequent calls to include a template do not invoke TemplateLoader.Load() if the template path exists in the cache, allowing stale compiled templates from previous renders to be served. Exploitation requires an application that pools TemplateContext objects, uses a request-dependent ITemplateLoader, and calls Reset() between requests. An attacker can prime the cache with authorized content and then access it in subsequent renders without proper authorization checks. The attack requires no authentication or user interaction and operates over the network. Scriban 7.0.0 and later fix this issue by clearing CachedTemplates during Reset().

Affected products

  • Scriban Scriban before 7.0.0

Timeline

  • 2026-03-22: disclosed
  • 2026-03-22: patched: Patch available in Scriban 7.0.0
  • 2026-08-16: advisory

References

Related threats