CRITICAL 9.3 NVD
CVE-2026-73061
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without se
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
References
- https://github.com/scriban/scriban/security/advisories/GHSA-7jvp-hj45-2f2m
- https://www.vulncheck.com/advisories/scriban-before-arbitrary-property-write-via-typedobje
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-16 via NVD.
Risk Timeline
CVE Disclosed2026-08-16 · -1 days ago
Remediation Resources
vulnfeed aggregates 11848 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.