mediumCVSS 4.7Vulnerability

CVE-2026-76802

A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates. **Affected Component** The issue is in the template loader's DAST loading branch. When `-dast` is enabled and a template contains a `fuzzing:` block, the loader accepted the template through a code path that omitted the unsigned-code-template signature check present in the normal loading branch. **Description** Nuclei requires `code:` protocol templates to be cryptographically signed before execution. Unsigned code templates are normally skipped with a warning. However, when a template combined a `fuzzing:` block (making it DAST-eligible) with an unsigned `code:` block, enabling `-dast` routed the template through the DAST loader branch, which did not enforce signature verification. For multiprotocol templates containing both HTTP and `code:` blocks, the unsigned code request was included in the execution queue regardless of whether `-code` was set. This allowed arbitrary shell command execution from an unsigned `code:` block with only `-dast` enabled. > [!NOTE] Both DAST mode (`-dast`) and code-protocol templates are disabled by default. Code templates normally require both the `-code` flag and a valid template signature. This issue bypassed the signature and `-code` controls only when `-dast` was explicitly enabled. **Affected Users** - **CLI users** running DAST/fuzzing scans (`-dast`) with untrusted or attacker-supplied templates that contain both `fuzzing:` and `code:` blocks. - **SDK users** who integrate Nuclei with DAST mode enabled and allow end users to supply custom templates. **Patches** - The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7472 **Mitigation** Upgrade to Nuclei v3.10.0, where code template signature

Properties

ghsa_id
GHSA-jpf4-98qj-qr67
severity
medium
summary
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
cvss_score
4.7
cve_id
CVE-2026-76802
cvss_vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-23T04:35:57+00:00
is_ghsa_only
false
ghsa_published
2026-09-22T20:37:16Z
source_url
https://github.com/advisories/GHSA-jpf4-98qj-qr67
ghsa_updated
2026-09-22T20:37:17Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

AFFECTS (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76802 (CVSS 4.7) — Ninja Signal Threat Intelligence | Ninja Signal