Scriban’s “Leaky” Cache: A 9.1 CVSS Sandbox Escape Hits 40 Million .NET Installs
ID: 867c5efa-256b-539e-afdf-2b414e182fe1
STIX ID: report--867c5efa-256b-539e-afdf-2b414e182fe1
Feed Name: securityonline.info
A critical CVSS 9.1 vulnerability in the Scriban .NET templating engine permits sandbox escapes due to cached TypedObjectAccessor instances that aren’t cleared on TemplateContext.Reset(), so tightening MemberFilter on reused contexts does not prevent exposure of previously allowed members. The flaw risks unauthorized data access and writes (including multi-tenant exposures) and affects Scriban up to 6.6.0; developers are advised to update to Scriban 7.0.0 which contains the fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
