PT-2026-73153 · Scriban · Scriban
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.0.0
Description
Three distinct denial-of-service issues exist in expression evaluation that bypass safety controls. These issues involve unbounded string multiplication, uncontrolled BigInteger shift operations, and a LoopLimit bypass via range enumeration in builtin functions. Attackers capable of supplying templates can trigger out-of-memory exceptions or CPU exhaustion, which typically results in the termination of the entire host process.
Recommendations
Update to version 7.0.0 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban