Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-16 14:16
Updated : 2026-09-08 20:32
NVD link : CVE-2026-74787
Mitre link : CVE-2026-74787
CVE.ORG link : CVE-2026-74787
JSON object : View
Products Affected
No product.
CWE
CWE-674
Uncontrolled Recursion
