CVE-2026-74787

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 14:16

Updated : 2026-09-08 20:32


NVD link : CVE-2026-74787

Mitre link : CVE-2026-74787

CVE.ORG link : CVE-2026-74787


JSON object : View

Products Affected

No product.

CWE
CWE-674

Uncontrolled Recursion