PT-2026-73152 · Scriban · Scriban
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.2.0
Description
A denial of service issue exists in the
array.insert at() function. The function allocates unbounded null entries and fails to respect LoopLimit or LimitToString constraints. An attacker can provide a large index parameter to trigger an OutOfMemoryException, which crashes the host process in less than a second.Recommendations
Update to version 7.2.0 or later.
As a temporary workaround, restrict the use of the
array.insert at() function.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban