CVE-2026-41646

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:*

History

08 May 2026, 19:42

Type Values Removed Values Added
References () https://github.com/projectdiscovery/nuclei/commit/6f2ade6a9b427c284c15a43445f9c7f055e60e5d - () https://github.com/projectdiscovery/nuclei/commit/6f2ade6a9b427c284c15a43445f9c7f055e60e5d - Patch
References () https://github.com/projectdiscovery/nuclei/pull/7332 - () https://github.com/projectdiscovery/nuclei/pull/7332 - Issue Tracking, Patch
References () https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-29rg-wmcw-hpf4 - () https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-29rg-wmcw-hpf4 - Mitigation, Patch, Vendor Advisory
CPE cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:*
First Time Projectdiscovery nuclei
Projectdiscovery

08 May 2026, 15:16

Type Values Removed Values Added
References () https://github.com/projectdiscovery/nuclei/pull/7332 - () https://github.com/projectdiscovery/nuclei/pull/7332 -

08 May 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 04:16

Updated : 2026-05-08 19:42


NVD link : CVE-2026-41646

Mitre link : CVE-2026-41646

CVE.ORG link : CVE-2026-41646


JSON object : View

Products Affected

projectdiscovery

  • nuclei
CWE
CWE-284

Improper Access Control