VDB
Sign up
MEDIUM4.7

GHSA-jpf4-98qj-qr67

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

Quick fix

GHSA-jpf4-98qj-qr67 — github.com/projectdiscovery/nuclei/v3: upgrade to the fixed version with the command below.

go get github.com/projectdiscovery/nuclei/v3@v3.10.0

Details

A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates.

**Affected Component**

The issue is in the template loader's DAST loading branch. When `-dast` is enabled and a template contains a `fuzzing:` block, the loader accepted the template through a code path that omitted the unsigned-code-template signature check present in the normal loading branch.

**Description**

Nuclei requires `code:` protocol templates to be cryptographically signed before execution. Unsigned code templates are normally skipped with a warning. However, when a template combined a `fuzzing:` block (making it DAST-eligible) with an unsigned `code:` block, enabling `-dast` routed the template through the DAST loader branch, which did not enforce signature verification.

For multiprotocol templates containing both HTTP and `code:` blocks, the unsigned code request was included in the execution queue regardless of whether `-code` was set. This allowed arbitrary shell command execution from an unsigned `code:` block with only `-dast` enabled.

> [!NOTE] Both DAST mode (`-dast`) and code-protocol templates are disabled by default. Code templates normally require both the `-code` flag and a valid template signature. This issue bypassed the signature and `-code` controls only when `-dast` was explicitly enabled.

**Affected Users**

- **CLI users** running DAST/fuzzing scans (`-dast`) with untrusted or attacker-supplied templates that contain both `fuzzing:` and `code:` blocks. - **SDK users** who integrate Nuclei with DAST mode enabled and allow end users to supply custom templates.

**Patches**

- The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7472

**Mitigation**

Upgrade to Nuclei v3.10.0, where code template signature verification is enforced before DAST loading.

In the meantime, avoid running DAST scans with untrusted templates.

**Workarounds**

If upgrading is not an option, do not use `-dast` with templates from unverified sources.

**Acknowledgments**

Thanks to @daffainfo for reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/projectdiscovery/nuclei/v3
Introduced in: 3.0.0Fixed in: 3.10.0
Fixgo get github.com/projectdiscovery/nuclei/v3@v3.10.0

References