CVE-2026-41282

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
20/04/2026
Last modified:
23/04/2026

Description

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:* 3.0.0 (including) 3.8.0 (excluding)