—
GO-2026-4965
Nuclei: Local File Read via require() Module Loader Bypass in github.com/projectdiscovery/nuclei
Details
Nuclei: Local File Read via require() Module Loader Bypass in github.com/projectdiscovery/nuclei
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/projectdiscovery/nuclei
Introduced in:
0 No fixed version published yet for github.com/projectdiscovery/nuclei (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/projectdiscovery/nuclei/v2
Introduced in:
0 No fixed version published yet for github.com/projectdiscovery/nuclei/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/projectdiscovery/nuclei/v3
Introduced in:
3.0.0 Fixed in: 3.8.0 Fix
go get github.com/projectdiscovery/nuclei/v3@v3.8.0 References
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-29rg-wmcw-hpf4 [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-41646 [ADVISORY]
- https://github.com/projectdiscovery/nuclei/commit/6f2ade6a9b427c284c15a43445f9c7f055e60e5d [FIX]
- https://github.com/projectdiscovery/nuclei/pull/7332 [FIX]