PT-2026-73148 · Scriban · Scriban

·

CVE-2026-73061

·

Published

2026-07-06

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scriban versions prior to 7.2.2
Description An access-modifier bypass exists in the TypedObjectAccessor component. This issue allows template code to write Common Language Runtime (CLR) object properties by bypassing setter-visibility checks. Consequently, an attacker can modify properties that have private, internal, or init-only setters and perform mass assignment on properties with public setters, leading to the permanent alteration of live host objects after the template is rendered.
Recommendations Update to version 7.2.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73061
GHSA-7JVP-HJ45-2F2M

Affected Products

Scriban