๐Ÿ” CVE Alert

CVE-2026-76802

MEDIUM 4.7

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an untrusted multiprotocol template can place an unsigned code request into the execution queue and run arbitrary shell commands even without -code or a valid cryptographic signature. The issue affects CLI DAST scans and SDK integrations that enable DAST while accepting attacker-supplied templates. This issue is fixed in version 3.10.0.

CWE CWE-78
Vendor projectdiscovery
Product nuclei
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for projectdiscovery nuclei

Be the first to know when new medium vulnerabilities affecting projectdiscovery nuclei are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

projectdiscovery / nuclei
>= 3.0.0, < 3.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpf4-98qj-qr67 github.com: https://github.com/projectdiscovery/nuclei/pull/7472 github.com: https://github.com/projectdiscovery/nuclei/commit/1c440e755a97471c56fb0276ee8a8c4132974645 github.com: https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0