Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/projectdiscovery/nuclei/v3
  4. ›
  5. CVE-2026-76819

CVE-2026-76819: Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

September 22, 2026

A vulnerability in the Goja JavaScript engine used by Nuclei’s javascript: protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.

Affected Component

The issue is in the Goja JavaScript runtime embedded in Nuclei’s JavaScript protocol (pkg/js/). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.

Description

Nuclei uses the Goja engine to execute javascript: protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei.

Because javascript: templates execute without the -code flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template’s init section, which runs during template initialization before other security checks complete.

[!NOTE] JavaScript templates do not require the -code flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth.

Affected Users

  • CLI users running untrusted or third-party javascript: templates.
  • SDK users who integrate Nuclei into platforms where end users can supply JavaScript templates.

Patches

  • The vulnerability is fixed in Nuclei v3.10.0 by updating the Goja dependency. Upgrading is strongly recommended.
  • Fix reference: https://github.com/projectdiscovery/nuclei/pull/7467
  • Additional hardening in v3.11.0 requires cryptographic signatures for JavaScript templates: https://github.com/projectdiscovery/nuclei/pull/7514

Mitigation

Upgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid signatures.

In the meantime, avoid running JavaScript templates from unverified sources.

Workarounds

If upgrading is not an option, do not run untrusted JavaScript templates. There is no configuration flag that mitigates native code execution on affected versions.

Acknowledgments

Thanks to Dylan Pindur (@dpindur) and Adam Kues (@akues-an) of the Assetnote security research team for reporting this issue through responsible disclosure via security@projectdiscovery.io.

References

  • github.com/advisories/GHSA-vxg7-f2jj-jmqm
  • github.com/projectdiscovery/nuclei/commit/1fe6025b966cbb95ed4d9f40abfb629b6cbd27b2
  • github.com/projectdiscovery/nuclei/pull/7467
  • github.com/projectdiscovery/nuclei/pull/7514
  • github.com/projectdiscovery/nuclei/releases/tag/v3.10.0
  • github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm
  • nvd.nist.gov/vuln/detail/CVE-2026-76819

Code Behaviors & Features

Detect and mitigate CVE-2026-76819 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.0 before 3.10.0

Fixed versions

  • 3.10.0

Solution

Upgrade to version 3.10.0 or above.

Impact 8.6 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-787: Out-of-bounds Write
  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

go/github.com/projectdiscovery/nuclei/v3/CVE-2026-76819.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 23 Sep 2026 00:17:42 +0000.