ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
References
| Link | Resource |
|---|---|
| https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb | Patch |
| https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3 | Patch |
| https://github.com/projectdiscovery/nuclei/pull/7221 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/pull/7321 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr | Vendor Advisory Mitigation |
| https://github.com/projectdiscovery/nuclei/pull/7221 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/pull/7321 | Issue Tracking |
Configurations
History
23 Apr 2026, 15:25
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:* | |
| References | () https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb - Patch | |
| References | () https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3 - Patch | |
| References | () https://github.com/projectdiscovery/nuclei/pull/7221 - Issue Tracking | |
| References | () https://github.com/projectdiscovery/nuclei/pull/7321 - Issue Tracking | |
| References | () https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr - Vendor Advisory, Mitigation | |
| First Time |
Projectdiscovery
Projectdiscovery nuclei |
20 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/projectdiscovery/nuclei/pull/7221 - | |
| References | () https://github.com/projectdiscovery/nuclei/pull/7321 - |
20 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 08:16
Updated : 2026-04-23 15:25
NVD link : CVE-2026-41282
Mitre link : CVE-2026-41282
CVE.ORG link : CVE-2026-41282
JSON object : View
Products Affected
projectdiscovery
- nuclei
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
