VulnerabilityAnalyzed
CVE-2026-41646
Nuclei is a vulnerability scanner built on a simple YAML-based DSL.
MEDIUM 5.5EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.11% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- projectdiscovery/nuclei
- Source
- security-advisories@github.com
References
- https://github.com/projectdiscovery/nuclei/commit/6f2ade6a9b427c284c15a43445f9c7f055e60e5dPatch
- https://github.com/projectdiscovery/nuclei/pull/7332Issue Tracking, Patch
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-29rg-wmcw-hpf4Mitigation, Patch, Vendor Advisory
- https://github.com/projectdiscovery/nuclei/pull/7332Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.