Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Scriban before version 7.0.0 contains a critical uncontrolled recursion vulnerability in its object.to_json builtin function. The flaw stems from the absence of depth limits and circular reference detection mechanisms, allowing attackers to craft malicious templates containing self-referencing objects that trigger unbounded recursion. When processed, these templates cause a StackOverflowException that fatally terminates the entire .NET hosting process, resulting in a denial of service. This vulnerability affects any application using Scriban for template processing—particularly those accepting user-supplied or untrusted templates—including content management systems, reporting engines, and dynamic configuration processors built on .NET platforms.
While this CVE maps to CWE-674 (Uncontrolled Recursion) rather than specific MITRE ATT&CK techniques, Casky's Claude AI-powered analysis would detect the attack pattern as resource exhaustion leading to service disruption. A practitioner using Casky would identify this vulnerability through detection of: abnormal template processing behavior, recursive function call chains in Scriban template execution logs, and process termination events correlated with template rendering activities. The extended reasoning capability would help security teams trace template sources, identify which applications embed vulnerable Scriban versions, and prioritize remediation by correlating template processing patterns with user inputs or external data sources that could be manipulated to exploit this recursion flaw.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-74787. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation