highCVSS 7.5Vulnerability

GHSA-grr9-747v-xvcp

When Scriban renders an object that contains a circular reference, it traverses the object's members infinitely. Because the `ObjectRecursionLimit` property defaults to unlimited, this behavior exhausts the thread's stack space, triggering an uncatchable `StackOverflowException` that immediately terminates the hosting process. When rendering objects (e.g., `{{ obj }}`), the Scriban rendering engine recursively inspects and formats the object's properties. To prevent infinite loops caused by deeply nested or circular data structures, `TemplateContext` contains an `ObjectRecursionLimit` property. However, this property currently defaults to `0` (unlimited). If the data context pushed into the template contains a circular reference, the renderer will recurse indefinitely. This is especially dangerous for web applications that map user-controlled payloads (like JSON) directly to rendering contexts, or for applications that pass ORM objects (like Entity Framework models, which frequently contain circular navigation properties) into the template. #### Proof of Concept (PoC) The following C# code demonstrates the vulnerability. Executing this will cause an immediate, fatal `StackOverflowException`, bypassing any standard error handling. ```csharp using Scriban; using Scriban.Runtime; var template = Template.Parse("{{ a }}"); var context = new TemplateContext(); var a = new ScriptObject(); // Introduce a cycle a["self"] = a; context.PushGlobal(new ScriptObject { { "a", a } }); try { // This crashes the entire process immediately template.Render(context); } catch (Exception ex) { // This will never execute because StackOverflowException Console.WriteLine("Caught exception: " + ex.Message); } ``` #### Impact This vulnerability allows a Denial of Service (DoS) attack. If a malicious user can manipulate the data structure passed to the renderer to include a cyclic reference, or if the application passes a complex object graph to an untrusted template, the entir

Properties

ghsa_id
GHSA-grr9-747v-xvcp
severity
high
summary
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
cvss_score
7.5
cve_id
GHSA-grr9-747v-xvcp
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-03-19T21:31:01Z
source_url
https://github.com/advisories/GHSA-grr9-747v-xvcp
ghsa_updated
2026-03-19T21:31:01Z

Related Entities (3)

AFFECTS (1)

[Software]nuget/Scriban

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Recursion

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph