GHSA-jpf4-98qj-qr67
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
Quick fix
GHSA-jpf4-98qj-qr67 — github.com/projectdiscovery/nuclei/v3: upgrade to the fixed version with the command below.
go get github.com/projectdiscovery/nuclei/v3@v3.10.0Details
A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates.
**Affected Component**
The issue is in the template loader's DAST loading branch. When `-dast` is enabled and a template contains a `fuzzing:` block, the loader accepted the template through a code path that omitted the unsigned-code-template signature check present in the normal loading branch.
**Description**
Nuclei requires `code:` protocol templates to be cryptographically signed before execution. Unsigned code templates are normally skipped with a warning. However, when a template combined a `fuzzing:` block (making it DAST-eligible) with an unsigned `code:` block, enabling `-dast` routed the template through the DAST loader branch, which did not enforce signature verification.
For multiprotocol templates containing both HTTP and `code:` blocks, the unsigned code request was included in the execution queue regardless of whether `-code` was set. This allowed arbitrary shell command execution from an unsigned `code:` block with only `-dast` enabled.
> [!NOTE] Both DAST mode (`-dast`) and code-protocol templates are disabled by default. Code templates normally require both the `-code` flag and a valid template signature. This issue bypassed the signature and `-code` controls only when `-dast` was explicitly enabled.
**Affected Users**
- **CLI users** running DAST/fuzzing scans (`-dast`) with untrusted or attacker-supplied templates that contain both `fuzzing:` and `code:` blocks. - **SDK users** who integrate Nuclei with DAST mode enabled and allow end users to supply custom templates.
**Patches**
- The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7472
**Mitigation**
Upgrade to Nuclei v3.10.0, where code template signature verification is enforced before DAST loading.
In the meantime, avoid running DAST scans with untrusted templates.
**Workarounds**
If upgrading is not an option, do not use `-dast` with templates from unverified sources.
**Acknowledgments**
Thanks to @daffainfo for reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.0Fixed in: 3.10.0go get github.com/projectdiscovery/nuclei/v3@v3.10.0References
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpf4-98qj-qr67[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-76802[ADVISORY]
- https://github.com/projectdiscovery/nuclei/pull/7472[WEB]
- https://github.com/projectdiscovery/nuclei/commit/1c440e755a97471c56fb0276ee8a8c4132974645[WEB]
- https://github.com/projectdiscovery/nuclei[PACKAGE]
- https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0[WEB]