
Scriban's TemplateContext.Reset() clears runtime state but not CachedTemplates. Pool the context across requests and tenant B renders tenant A's template. CVE-2026-74791, High. Write-up: https://offensive360.com/zerodays/cve-2026-74791-scriban/?utm_source=x&utm_medium=social&utm_campaign=daily&utm_content=20260909 #CVE #AppSec https://t.co/ZB63XYAlnt
Post summary
Scriban’s TemplateContext.Reset() flaw (CVE‑2026‑74791, high severity) allows tenant isolation bypass via cached templates; a write‑up with details is linked.


