Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 16 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering. | |
| Title | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-16T13:14:07.946Z
Reserved: 2026-08-10T19:10:18.101Z
Link: CVE-2026-73061
No data.
Status : Received
Published: 2026-08-16T14:16:55.770
Modified: 2026-08-16T14:16:55.770
Link: CVE-2026-73061
No data.
OpenCVE Enrichment
Updated: 2026-08-16T14:45:04Z
Weaknesses