Local File Access Vulnerability in Nuclei Scanner by Project Discovery
CVE-2026-76803

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-76803?

The Nuclei vulnerability scanner versions 3.0.0 to 3.10.0 contains a significant flaw wherein the nuclei/mysql JavaScript library fails to enforce a local-file sandbox when processing JavaScript templates. Specifically, if a JavaScript template specifies the allowAllFiles MySQL DSN option, it allows scanning against an attacker-controlled MySQL-compatible endpoint. This could result in the server executing LOAD DATA LOCAL INFILE requests that access arbitrary file paths, causing sensitive files to be read and returned to the attacker. Notably, this issue affects both CLI and SDK deployments that utilize untrusted templates. The vulnerability has been resolved in version 3.10.0.

Affected Version(s)

nuclei >= 3.0.0, < 3.10.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.