mediumCVSS 5.3Vulnerability

CVE-2026-76805

A vulnerability in Nuclei's DAST/fuzz expression evaluation path allows a malicious target server to trigger disclosure of scanner-host environment variables when the `-env-vars` / `-ev` option is explicitly enabled. This is an incomplete fix for [CVE-2026-41645](https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr) / GHSA-jm34-66cf-qpvr. The original fix hardened `expressions.Evaluate()` to be single-pass within one call, but did not address callers that invoked evaluation multiple times on substituted output in the DAST/fuzz pipeline. **Affected Component** The issue is in the DAST/fuzz payload evaluation path (`pkg/fuzz/parts.go`) and the shared template rendering boundary. When a multi-step template captures response data via an internal extractor and reuses it in a subsequent fuzz step, the fuzz evaluator could treat the substituted response content as fresh template syntax on a second evaluation pass. **Description** In DAST/fuzz mode, payload evaluation previously ran expression substitution more than once on the same value. Response-derived content captured by an `internal: true` extractor in a prior protocol step could flow into a fuzz payload and be reinterpreted as DSL/helper syntax on a subsequent pass. When `-env-vars` (`-ev`) is enabled, environment variables are merged into the template variable map. A malicious target can return response data containing expressions like `{{env_var_name}}` which, when reused in a subsequent fuzz step, resolve to actual environment variable values. This can expose sensitive host data such as API keys, credentials, and tokens. Without `-ev` enabled (the default), response-derived data may still cause other DSL helpers to run, but that behavior is not treated as a security issue and has no meaningful security impact beyond unexpected behavior. > [!NOTE] The `-env-vars` / `-ev` option is off by default. Users who have not explicitly enabled it are not affected by this vulnerability.

Properties

ghsa_id
GHSA-jpvm-9frm-hjcq
severity
medium
summary
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
cvss_score
5.3
cve_id
CVE-2026-76805
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
signal_observed_at
2026-09-23T04:35:57+00:00
is_ghsa_only
false
ghsa_published
2026-09-22T20:37:24Z
source_url
https://github.com/advisories/GHSA-jpvm-9frm-hjcq
ghsa_updated
2026-09-22T20:37:27Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

AFFECTS (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76805 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal