DescriptionScriban before 6.6.0 contains a denial of service vulnerability where TemplateContext.LimitToString defaults to unlimited, allowing attackers to cause memory exhaustion through exponential string growth. Attackers can supply malicious templates with repeated string concatenation operations that allocate gigabytes of memory in seconds, exhausting heap resources and crashing the host process.