CVE-2026-74787

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/08/2026
Last modified:
16/08/2026

Description

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.