CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 14:16

Updated : 2026-08-31 20:30


NVD link : CVE-2026-74791

Mitre link : CVE-2026-74791

CVE.ORG link : CVE-2026-74791


JSON object : View

Products Affected

No product.

CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse