Further research determined the issue results from a dependency.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vxg7-f2jj-jmqm | Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
No reference.
History
Tue, 22 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0. | Further research determined the issue results from a dependency. |
| Title | Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability | |
| Weaknesses | CWE-787 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Tue, 22 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0. | |
| Title | Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability | |
| Weaknesses | CWE-787 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T16:45:29.510Z
Reserved: 2026-08-19T19:52:28.213Z
Link: CVE-2026-76819
No data.
Status : Rejected
Published: 2026-09-22T17:17:25.230
Modified: 2026-09-22T17:17:25.230
Link: CVE-2026-76819
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
Github GHSA