{"id":"GHSA-jpf4-98qj-qr67","summary":"Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass","details":"A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates.\n\n**Affected Component**\n\nThe issue is in the template loader's DAST loading branch. When `-dast` is enabled and a template contains a `fuzzing:` block, the loader accepted the template through a code path that omitted the unsigned-code-template signature check present in the normal loading branch.\n\n**Description**\n\nNuclei requires `code:` protocol templates to be cryptographically signed before execution. Unsigned code templates are normally skipped with a warning. However, when a template combined a `fuzzing:` block (making it DAST-eligible) with an unsigned `code:` block, enabling `-dast` routed the template through the DAST loader branch, which did not enforce signature verification.\n\nFor multiprotocol templates containing both HTTP and `code:` blocks, the unsigned code request was included in the execution queue regardless of whether `-code` was set. This allowed arbitrary shell command execution from an unsigned `code:` block with only `-dast` enabled.\n\n\u003e [!NOTE]\nBoth DAST mode (`-dast`) and code-protocol templates are disabled by default. Code templates normally require both the `-code` flag and a valid template signature. This issue bypassed the signature and `-code` controls only when `-dast` was explicitly enabled.\n\n**Affected Users**\n\n- **CLI users** running DAST/fuzzing scans (`-dast`) with untrusted or attacker-supplied templates that contain both `fuzzing:` and `code:` blocks.\n- **SDK users** who integrate Nuclei with DAST mode enabled and allow end users to supply custom templates.\n\n**Patches**\n\n- The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended.\n- Fix reference: https://github.com/projectdiscovery/nuclei/pull/7472\n\n**Mitigation**\n\nUpgrade to Nuclei v3.10.0, where code template signature verification is enforced before DAST loading.\n\nIn the meantime, avoid running DAST scans with untrusted templates.\n\n**Workarounds**\n\nIf upgrading is not an option, do not use `-dast` with templates from unverified sources.\n\n**Acknowledgments**\n\nThanks to @daffainfo for reporting this issue.","aliases":["CVE-2026-76802","GO-2026-6570"],"modified":"2026-10-01T20:56:12.209632510Z","published":"2026-09-22T20:37:16Z","database_specific":{"github_reviewed_at":"2026-09-22T20:37:16Z","nvd_published_at":"2026-09-22T17:17:24Z","cwe_ids":["CWE-78"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpf4-98qj-qr67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76802"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/pull/7472"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/commit/1c440e755a97471c56fb0276ee8a8c4132974645"},{"type":"PACKAGE","url":"https://github.com/projectdiscovery/nuclei"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0"}],"affected":[{"package":{"name":"github.com/projectdiscovery/nuclei/v3","ecosystem":"Go","purl":"pkg:golang/github.com/projectdiscovery/nuclei/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-jpf4-98qj-qr67/GHSA-jpf4-98qj-qr67.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}