MemberFilter Bypass Vulnerability in Scriban by Scriban
CVE-2026-74790
9.3CRITICAL
What is CVE-2026-74790?
Scriban versions earlier than 7.0.0 exhibit a critical vulnerability where the caching mechanism for TypedObjectAccessor does not account for changes in MemberFilter settings. This oversight allows an attacker to leverage reused TemplateContext instances, ultimately exposing restricted members that should be kept hidden. As a consequence, tighter MemberFilter configurations can be bypassed, leading to unauthorized access across different requests or tenants and compromising the intended sandboxing measures.
Affected Version(s)
scriban 0 < 7.0.0
scriban 7.0.0
