15 Total advisories
15 Vulnerabilities
0 Malware
Dependency scanning
Check whether scriban is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-73062
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
HIGH 8.6
CVE-2026-74791
Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()
UNKNOWN
CVE-2026-73061
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
CRITICAL 9.1
CVE-2026-74790
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse
MEDIUM 6.5
CVE-2026-74786
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
HIGH 7.5
CVE-2026-74788
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
UNKNOWN
CVE-2026-74784
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
MEDIUM 6.5
CVE-2026-74785
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
HIGH 7.5
CVE-2026-74795
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
HIGH 7.5
CVE-2026-74787
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
HIGH 7.5
CVE-2026-74789
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
HIGH 7.5
CVE-2026-74794
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
HIGH 7.5
CVE-2026-74792
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
UNKNOWN
CVE-2026-74783
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
MEDIUM 5.3
GHSA-5rpf-x9jg-8j5p
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)
Browse more NuGet advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes