What is CVE-2026-73061?
Scriban versions before 7.2.2 contain an access-modifier bypass vulnerability in TypedObjectAccessor, allowing template code to write to CLR object properties with private, internal, or init-only setters. This could enable attackers to perform mass assignment on public-facing objects. Affected users should upgrade to version 7.2.2 or later immediately.
Azərbaycanca: Scriban şablon mühərrikinin 7.2.2-dən əvvəlki versiyalarında TypedObjectAccessor-da access-modifier bypass zəifliyi mövcuddur ki, bu, şablon koduna CLR obyektlərinin private, internal və ya init-only setter-ləri olan xassələrini yazmağa imkan verir. Bu zəiflik hücumçulara kütləvi təyinat (mass assignment) həyata keçirməyə şərait yaradır. Təsirə məruz qalan istifadəçilər dərhal 7.2.2 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What does the CVE-2026-73061 vulnerability in Scriban template engine allow?
This vulnerability allows template code to write to CLR object properties with private, internal, or init-only setters, which could enable attackers to perform mass assignment on public-facing objects.
Which versions of Scriban are affected by CVE-2026-73061 and how to protect?
Scriban versions before 7.2.2 are affected. Users should upgrade to version 7.2.2 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.