Scriban is vulnerable to Sandbox Bypass
93
Critical Risk
TemplateContext.GetMemberAccessor() caches TypedObjectAccessor instances by Type only, even though each accessor is built from the current MemberFilter and MemberRenamer. Reusing a TemplateContext after tightening MemberFilter still serves the older permissive accessor, so templates can read or write members that the updated filter was meant to hide. Applications that pool contexts across requests or tenants can therefore bypass sandbox exposure policies. The fix resets the typed accessor cache when MemberFilter changes.
You are affected if you are using a version that falls within the vulnerable range and reuse a TemplateContext while relying on MemberFilter to hide members.
Scriban is vulnerable to Sandbox Bypass in versions 0.0.0 - 6.6.0.
Upgrade the Scriban library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant