PT-2026-73155 · Scriban · Scriban
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.0.0
Description
An uncontrolled recursion issue exists in the
object.to json() builtin function due to a lack of depth limits and circular reference detection. An attacker can create templates containing self-referencing objects to trigger unbounded recursion, resulting in a StackOverflowException that crashes the hosting .NET process.Recommendations
Update to version 7.0.0 or later.
As a temporary mitigation, avoid using the
object.to json() function with untrusted or complex objects.Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban