highCVSS 8.6Vulnerability

CVE-2026-76819

A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates. **Affected Component** The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (`pkg/js/`). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation. **Description** Nuclei uses the Goja engine to execute `javascript:` protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei. Because `javascript:` templates execute without the `-code` flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template's `init` section, which runs during template initialization before other security checks complete. > [!NOTE] JavaScript templates do not require the `-code` flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth. **Affected Users** - **CLI users** running untrusted or third-party `javascript:` templates. - **SDK users** who integrate Nuclei into platforms where end users can supply JavaScript templates. **Patches** - The vulnerability is fixed in Nuclei v3.10.0 by updating the Goja dependency. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7467 - Additional hardening in v3.11.0 requires cryptographic signatures for JavaScript templates: https://github.com/projectdiscovery/nuclei/pull/7514 **Mitigation** Upgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid sign

Properties

ghsa_id
GHSA-vxg7-f2jj-jmqm
summary
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
severity
high
cvss_score
8.6
cve_id
CVE-2026-76819
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
signal_observed_at
2026-09-23T04:35:57+00:00
is_ghsa_only
false
ghsa_published
2026-09-22T20:37:13Z
source_url
https://github.com/advisories/GHSA-vxg7-f2jj-jmqm
ghsa_updated
2026-09-22T20:37:17Z

Related Entities (5)

HAS_WEAKNESS (2)

[Weakness]Improper Control of Generation of Code ('Code Injection')
[Weakness]Out-of-bounds Write

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

AFFECTS (1)

[Software]go/github.com/projectdiscovery/nuclei/v3

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76819 (CVSS 8.6) — Ninja Signal Threat Intelligence | Ninja Signal