PT-2026-73158 · Scriban · Scriban
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.0.0
Description
Scriban caches TypedObjectAccessor based solely on the type, ignoring changes made to the MemberFilter. This behavior allows reused TemplateContext instances to expose members that were intended to be hidden. An attacker can bypass sandbox policies across different requests or tenants by reusing a TemplateContext after its MemberFilter has been tightened, thereby gaining access to filtered properties and fields.
Recommendations
Update to version 7.0.0 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban