MemberFilter Bypass Vulnerability in Scriban by Scriban
CVE-2026-74790

9.3CRITICAL

Key Information:

Vendor

Scriban

Status
Vendor
CVE Published:
16 August 2026

What is CVE-2026-74790?

Scriban versions earlier than 7.0.0 exhibit a critical vulnerability where the caching mechanism for TypedObjectAccessor does not account for changes in MemberFilter settings. This oversight allows an attacker to leverage reused TemplateContext instances, ultimately exposing restricted members that should be kept hidden. As a consequence, tighter MemberFilter configurations can be bypassed, leading to unauthorized access across different requests or tenants and compromising the intended sandboxing measures.

Affected Version(s)

scriban 0 < 7.0.0

scriban 7.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zwique
.