ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
References
| Link | Resource |
|---|---|
| https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb | Patch |
| https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3 | Patch |
| https://github.com/projectdiscovery/nuclei/pull/7221 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/pull/7321 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr | Mitigation Vendor Advisory |
| https://github.com/projectdiscovery/nuclei/pull/7221 | Issue Tracking |
| https://github.com/projectdiscovery/nuclei/pull/7321 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-04-20 08:16
Updated : 2026-06-17 10:46
NVD link : CVE-2026-41282
Mitre link : CVE-2026-41282
CVE.ORG link : CVE-2026-41282
JSON object : View
Products Affected
projectdiscovery
- nuclei
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
