Launch Week Day 1: Announcing Security Design Review
12 Total advisories
12 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
NuGet

GHSA-24c8-4792-22hx

Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString

CRITICAL 9.1
NuGet

GHSA-5wr9-m6jw-xx44

Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse

HIGH 8.6
NuGet

GHSA-x6m9-38vm-2xhf

Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()

HIGH 7.5
NuGet

GHSA-xcx6-vp38-8hr5

Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException

MEDIUM 6.5
NuGet

GHSA-m2p3-hwv5-xpqw

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

MEDIUM 6.5
NuGet

GHSA-xw6w-9jjh-p9cr

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

HIGH 7.5
NuGet

GHSA-v66j-x4hw-fv9g

Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service

HIGH 7.5
NuGet

GHSA-c875-h985-hvrc

Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service

HIGH 7.5
NuGet

GHSA-p6q4-fgr8-vx4p

Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix

HIGH 7.5
NuGet

GHSA-wgh7-7m3c-fx25

Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)

MEDIUM 5.3
NuGet

GHSA-5rpf-x9jg-8j5p

Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)

HIGH 7.5
NuGet

GHSA-grr9-747v-xvcp

Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)

Ready to move

Start Securing

Free, no credit card | First findings in minutes