LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-74790

Published
CVSS9.1
Severitycritical
WeaknessCWE-693
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74790

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74790.