CVE-2026-41282

Published
View on NVD ↗
CVSS v3
4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
GitHubGitHub
29.1K