CVE-2026-74791
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-226
Información sensible no eliminada antes de su liberación
Fecha de publicación:
16/08/2026
Última modificación:
16/08/2026
Descripción
*** Pendiente de traducción *** Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.
Impacto
Puntuación base 4.0
9.20
Gravedad 4.0
CRÍTICA
Puntuación base 3.x
8.60
Gravedad 3.x
ALTA



