Junglewise Threat Intelligence

Scriban arbitrary property write via TypedObjectAccessor setter bypass

Severity: high · CVSS 7.7 · Published 2026-07-06

Technologies: Scriban. Vendors: NuGet.

Executive brief

Scriban, a popular text templating engine for .NET, contains a vulnerability that allows templates to modify data they should only be able to read. When a developer passes a C# object to a template, the template can overwrite the object's properties, including those marked as private, internal, or read-only (init). This could allow an attacker who can control a template to escalate privileges, change administrative settings, or corrupt application data.

Technical details

The Scriban templating engine's TypedObjectAccessor fails to validate setter visibility or the CanWrite property when processing member assignments. This leads to two distinct issues: (1) Mass Assignment (CWE-915), where any public property is writable because Scriban lacks a read-only member filter, and (2) Access Modifier Bypass (CWE-284), where .NET reflection is used to write to private, internal, or C# 9 'init-only' setters. An attacker capable of providing or influencing a template can modify the state of live host objects passed into the TemplateContext. The vulnerability affects all versions up to 7.2.1; a fix involves explicitly checking for public setters and the IsExternalInit modifier during property access.

Affected products

  • Scriban Scriban <= 7.2.1

Timeline

  • 2026-05-30: disclosed: Initial disclosure to vendor
  • 2026-07-06: advisory: GitHub Advisory published

References

Related threats