Security Flaw in Nuclei Scanner Allowing Arbitrary Command Execution
CVE-2026-76802
What is CVE-2026-76802?
Nuclei, a vulnerability scanner by Project Discovery, has a security issue in versions 3.0.0 to 3.10.0. The DAST template loading process fails to perform a necessary check for the unsigned code-template signature, leaving it open to exploitation. An attacker can exploit this flaw by supplying a manipulated multi-protocol template containing an unsigned code block. When the DAST mode is enabled, the malicious template can submit arbitrary shell commands to the execution queue, potentially executing harmful operations without requiring a valid cryptographic signature or the -code parameter. This vulnerability affects CLI DAST scans and SDK integrations that accept user-provided templates. The issue has been resolved in version 3.10.0.
Affected Version(s)
nuclei >= 3.0.0, < 3.10.0