File Access Vulnerability in Nuclei Scanner by ProjectDiscovery
CVE-2026-76804
5.5MEDIUM
What is CVE-2026-76804?
Nuclei versions 3.0.0 to 3.10.0 are susceptible to a file access vulnerability, allowing untrusted unsigned workflows to load file-protocol templates. This flaw enables unauthorized access to local files on the scanner host, particularly affecting CLI users and SDK integrations utilizing default file-access restrictions. The vulnerability is addressed in version 3.10.0.
Affected Version(s)
nuclei >= 3.0.0, < 3.10.0