VulnSea

scriban has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 3. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-770 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
4 prev 2

Products

  • scriban 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

scriban vulnerabilities

CVEs affecting scriban, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-73060High· 7.5PoC
1mo ago

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multipli…

▾ Midnightscriban · scribanEPSS 0.67%via NVD
CVE-2026-74783High· 7.5PoC
1mo ago

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initi…

▾ Midnightscriban · scribanEPSS 0.49%via NVD
CVE-2026-73062High· 7.5PoC
1mo ago

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large intege…

▾ Midnightscriban · scribanEPSS 0.49%via NVD
GHSA-7jvp-hj45-2f2mHigh
2mo ago

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

▾ TwilightScriban · Scribanvia GHSA
GHSA-q6rr-fm2g-g5x8Medium
3mo ago

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

▾ SunlitScriban · Scribanvia GHSA
GHSA-6q7j-xr26-3h2cMedium
3mo ago

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

▾ SunlitScriban · Scribanvia GHSA
scriban vulnerabilities (CVEs) · VulnSea