Retour à la veille

CVE-2026-74791

Publié : 16 août 2026
Modifié : 16 août 2026
Lien officiel NVD
Score CVSS
8.6
HIGH

Description détaillée

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Références et Patchs

Dernières Vulnérabilités