GHSA-vxg7-f2jj-jmqm
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
Quick fix
GHSA-vxg7-f2jj-jmqm — github.com/projectdiscovery/nuclei/v3: upgrade to the fixed version with the command below.
go get github.com/projectdiscovery/nuclei/v3@v3.10.0Details
A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.
**Affected Component**
The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (`pkg/js/`). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.
**Description**
Nuclei uses the Goja engine to execute `javascript:` protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei.
Because `javascript:` templates execute without the `-code` flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template's `init` section, which runs during template initialization before other security checks complete.
> [!NOTE] JavaScript templates do not require the `-code` flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth.
**Affected Users**
- **CLI users** running untrusted or third-party `javascript:` templates. - **SDK users** who integrate Nuclei into platforms where end users can supply JavaScript templates.
**Patches**
- The vulnerability is fixed in Nuclei v3.10.0 by updating the Goja dependency. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7467 - Additional hardening in v3.11.0 requires cryptographic signatures for JavaScript templates: https://github.com/projectdiscovery/nuclei/pull/7514
**Mitigation**
Upgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid signatures.
In the meantime, avoid running JavaScript templates from unverified sources.
**Workarounds**
If upgrading is not an option, do not run untrusted JavaScript templates. There is no configuration flag that mitigates native code execution on affected versions.
**Acknowledgments**
Thanks to Dylan Pindur ([@dpindur](https://github.com/dpindur)) and Adam Kues ([@akues-an](https://github.com/akues-an)) of the Assetnote security research team for reporting this issue through responsible disclosure via security@projectdiscovery.io.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.0Fixed in: 3.10.0go get github.com/projectdiscovery/nuclei/v3@v3.10.0References
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-76819[ADVISORY]
- https://github.com/projectdiscovery/nuclei/pull/7467[WEB]
- https://github.com/projectdiscovery/nuclei/pull/7514[WEB]
- https://github.com/projectdiscovery/nuclei/commit/1fe6025b966cbb95ed4d9f40abfb629b6cbd27b2[WEB]
- https://github.com/projectdiscovery/nuclei[PACKAGE]
- https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0[WEB]