Description
Further research determined the issue results from a dependency.
Published: 2026-09-22
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Tue, 22 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0. Further research determined the issue results from a dependency.
Title Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
Weaknesses CWE-787
CWE-94
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Tue, 22 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0.
Title Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
Weaknesses CWE-787
CWE-94
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: REJECTED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T16:45:29.510Z

Reserved: 2026-08-19T19:52:28.213Z

Link: CVE-2026-76819

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2026-09-22T17:17:25.230

Modified: 2026-09-22T17:17:25.230

Link: CVE-2026-76819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.