PT-2026-73148 · Scriban · Scriban
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.2.2
Description
An access-modifier bypass exists in the
TypedObjectAccessor component. This issue allows template code to write Common Language Runtime (CLR) object properties by bypassing setter-visibility checks. Consequently, an attacker can modify properties that have private, internal, or init-only setters and perform mass assignment on properties with public setters, leading to the permanent alteration of live host objects after the template is rendered.Recommendations
Update to version 7.2.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scriban