CVE-2026-76802
A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates. **Affected Component** The issue is in the template loader's DAST loading branch. When `-dast` is enabled and a template contains a `fuzzing:` block, the loader accepted the template through a code path that omitted the unsigned-code-template signature check present in the normal loading branch. **Description** Nuclei requires `code:` protocol templates to be cryptographically signed before execution. Unsigned code templates are normally skipped with a warning. However, when a template combined a `fuzzing:` block (making it DAST-eligible) with an unsigned `code:` block, enabling `-dast` routed the template through the DAST loader branch, which did not enforce signature verification. For multiprotocol templates containing both HTTP and `code:` blocks, the unsigned code request was included in the execution queue regardless of whether `-code` was set. This allowed arbitrary shell command execution from an unsigned `code:` block with only `-dast` enabled. > [!NOTE] Both DAST mode (`-dast`) and code-protocol templates are disabled by default. Code templates normally require both the `-code` flag and a valid template signature. This issue bypassed the signature and `-code` controls only when `-dast` was explicitly enabled. **Affected Users** - **CLI users** running DAST/fuzzing scans (`-dast`) with untrusted or attacker-supplied templates that contain both `fuzzing:` and `code:` blocks. - **SDK users** who integrate Nuclei with DAST mode enabled and allow end users to supply custom templates. **Patches** - The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7472 **Mitigation** Upgrade to Nuclei v3.10.0, where code template signature
Properties
- ghsa_id
- GHSA-jpf4-98qj-qr67
- severity
- medium
- summary
- Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
- cvss_score
- 4.7
- cve_id
- CVE-2026-76802
- cvss_vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- signal_observed_at
- 2026-09-23T04:35:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-22T20:37:16Z
- source_url
- https://github.com/advisories/GHSA-jpf4-98qj-qr67
- ghsa_updated
- 2026-09-22T20:37:17Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph