CRITICAL 9.2 NVD

CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused co

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

References

Published: 2026-08-16 · Source: NVD · Feed updated: 2026-08-16
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-16 via NVD.

Risk Timeline

CVE Disclosed2026-08-16 · -1 days ago

Remediation Resources

vulnfeed aggregates 11848 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.