mediumCVSS 5.5Vulnerability

CVE-2026-76804

A vulnerability in Nuclei's workflow template loader allows `file:` protocol templates to execute without the `-file` flag, bypassing a security gate that is meant to prevent local file reads on the scanner host. **Affected Component** The issue is in the workflow template loading path. The main template loader enforces the `-file` gate for file-protocol templates, but the workflow loader did not apply the same check when resolving templates referenced by a workflow. **Description** Nuclei disables file-protocol templates by default because they read local files from the host running the scanner. Operators must explicitly enable them with the `-file` flag. When a workflow references a file-protocol template, the workflow loader accepted and executed that template without verifying that `-file` was enabled. Because workflows run unsigned by default, an untrusted workflow could load and execute a file-protocol template and read local files from the scan target path, even though the operator had not enabled file templates. > [!NOTE] File-protocol templates are disabled by default. This issue only affects users who run workflows from untrusted sources without having explicitly enabled `-file`. **Affected Users** - **CLI users** running workflows (`-w`) that reference file-protocol templates from untrusted or third-party sources. - **SDK users** who integrate Nuclei into platforms where end users can supply workflow files and rely on the default `-file` restriction to block local file access. **Patches** - The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7489 **Mitigation** Upgrade to Nuclei v3.10.0, where template execution requirements (including the `-file` gate) are enforced consistently across the main loader, workflow parsing, and request compilation paths. In the meantime, avoid running workflows from unverified sources. **Workarounds** If upgrading is n

Properties

ghsa_id
GHSA-qgw5-7j4f-fg97
severity
medium
summary
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
cvss_score
5.5
cve_id
CVE-2026-76804
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
signal_observed_at
2026-09-23T04:35:57+00:00
is_ghsa_only
false
ghsa_published
2026-09-22T20:37:21Z
source_url
https://github.com/advisories/GHSA-qgw5-7j4f-fg97
ghsa_updated
2026-09-22T20:37:22Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

AFFECTS (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76804 (CVSS 5.5) — Ninja Signal Threat Intelligence | Ninja Signal