CVE-2026-41282 PUBLISHED

Assigner: mitre
Reserved: 20.04.2026 Published: 20.04.2026 Updated: 20.04.2026

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 4

Product Status

Vendor ProjectDiscovery
Product Nuclei
Versions Default: unaffected
  • affected from 3.0.0 to 3.8.0 (excl.)

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE