HIGH
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection
Published Apr 20, 2026
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
Affected products
-
Affected
- ≥ 3.0.0, < 3.8.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| ProjectDiscovery | Nuclei | unaffected | Affected
|
- ≥ 3.0.0 · < 3.8.0
No data.
No Red Hat product state for this CVE.
github.com/projectdiscovery/nuclei/v3
Go
Introduced 3.0.0 Fixed 3.8.0github.com/projectdiscovery/nuclei
Go
Introduced 0 Fixed not fixedgithub.com/projectdiscovery/nuclei/v2
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/projectdiscovery/nuclei/v3 | 3.0.0 | 3.8.0 |
| Go | github.com/projectdiscovery/nuclei | 0 | not fixed |
| Go | github.com/projectdiscovery/nuclei/v2 | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23795 Advisory
- https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb Patch
- https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3 Patch
- https://github.com/projectdiscovery/nuclei/pull/7221 exploitIssue Tracking
- https://github.com/projectdiscovery/nuclei/pull/7321 exploitIssue Tracking
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23795 | Advisory | |
| https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb | Patch | |
| https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3 | Patch | |
| https://github.com/projectdiscovery/nuclei/pull/7221 | exploitIssue Tracking | |
| https://github.com/projectdiscovery/nuclei/pull/7321 | exploitIssue Tracking | |
| https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 20, 2026
Updated Apr 21, 2026
Reserved Apr 20, 2026
Link CVE-2026-41282
CISA Vulnrichment
Updated Apr 20, 2026
Red Hat
No data
GitHub
No data