Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scriban
Scriban scriban |
|
| Vendors & Products |
Scriban
Scriban scriban |
Sun, 16 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again. | |
| Title | Scriban before 7.0.0 Authorization Bypass via Stale Include Cache | |
| Weaknesses | CWE-226 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-16T13:14:15.049Z
Reserved: 2026-08-16T12:56:02.577Z
Link: CVE-2026-74791
No data.
Status : Received
Published: 2026-08-16T14:16:57.183
Modified: 2026-08-16T14:16:57.183
Link: CVE-2026-74791
No data.
OpenCVE Enrichment
Updated: 2026-08-17T10:58:33Z
Weaknesses