Technology · NuGet
scriban (NuGet) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in scriban (NuGet): 0 in the last 7 days and 9 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-74795, was published on 16 August 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 2
- Exploited in the wild
- 0
About scriban (NuGet)
A fast, built-in text-based template engine for .NET.
Latest scriban (NuGet) vulnerabilities
- CVE-2026-74795: Scriban uncontrolled recursion stack overflow in parserhighCVSS 7.5EPSS 0.6%
- CVE-2026-74794: Scriban infinite recursion in object renderinghighCVSS 7.5EPSS 0.5%
- CVE-2026-74792: Scriban stack overflow in nested array initializer parsinghighCVSS 7.5EPSS 0.5%
- CVE-2026-74791: Scriban authorization bypass via stale include cachehighCVSS 8.6EPSS 0.4%
- CVE-2026-74790: Scriban TypedObjectAccessor cache MemberFilter bypasscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-74789: Scriban LoopLimit denial-of-service bypass in built-in operationshighCVSS 7.5EPSS 0.6%
- CVE-2026-74788: Scriban uncontrolled memory allocation in string.pad_left and string.pad_righthighCVSS 7.5EPSS 0.5%
- CVE-2026-73061: Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` /…mediumCVSS 4EPSS 0.5%
- Scriban arbitrary property write via TypedObjectAccessor setter bypasshighCVSS 7.7
- Scriban stack overflow via non-enforcing parser depth limitmediumCVSS 7.5
- CVE-2026-74783: Scriban: ExpressionDepthLimit guard is non-enforcing , parser-recursion DoS in 6.6.0, 7.2.0 (incomplete fix for…mediumCVSS 4EPSS 0.5%
- CVE-2026-73062: Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit , incomplete fix for GHSA-c875-h985-hvrc, missed…mediumCVSS 4EPSS 0.5%
- Scriban uncontrolled memory allocation in array multiplicationmediumCVSS 8.7
- Scriban unbounded memory allocation in array.insert_athighCVSS 8.7
- CVE-2026-74784: Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToStringmediumCVSS 4EPSS 0.4%
- Scriban denial of service via unbounded resource consumptionmediumCVSS 6.5
- CVE-2026-74785: Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression EvaluationlowCVSS 3.1EPSS 0.5%
- Scriban denial of service via unbounded cumulative template outputmediumCVSS 6.5
- CVE-2026-74786: Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToStringlowCVSS 3.1EPSS 0.5%
- Scriban uncontrolled recursion in object.to_jsonhighCVSS 7.5
- CVE-2026-74787: Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowExceptionlowCVSS 3.1EPSS 0.5%
- Scriban uncontrolled memory allocation in string padding functionshighCVSS 7.5
- Scriban uncontrolled resource consumption via LoopLimit bypasshighCVSS 7.5
- Scriban sandbox escape via stale MemberFilter cache in TemplateContextcriticalCVSS 9.1
- Scriban information disclosure via stale include cache in TemplateContexthighCVSS 8.6
Most severe scriban (NuGet) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-74790: Scriban TypedObjectAccessor cache MemberFilter bypasscriticalCVSS 9.1EPSS 0.5%
- Scriban sandbox escape via stale MemberFilter cache in TemplateContextcriticalCVSS 9.1
- Scriban unbounded memory allocation in array.insert_athighCVSS 8.7
- CVE-2026-74791: Scriban authorization bypass via stale include cachehighCVSS 8.6EPSS 0.4%
- Scriban information disclosure via stale include cache in TemplateContexthighCVSS 8.6
- Scriban arbitrary property write via TypedObjectAccessor setter bypasshighCVSS 7.7
- CVE-2026-74789: Scriban LoopLimit denial-of-service bypass in built-in operationshighCVSS 7.5EPSS 0.6%
- CVE-2026-74795: Scriban uncontrolled recursion stack overflow in parserhighCVSS 7.5EPSS 0.6%
- CVE-2026-74792: Scriban stack overflow in nested array initializer parsinghighCVSS 7.5EPSS 0.5%
- CVE-2026-74794: Scriban infinite recursion in object renderinghighCVSS 7.5EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 7 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/scriban.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "scriban (NuGet) vulnerabilities", https://junglewise.ai/threats/technologies/scriban, 28 September 2026.