{"id":"GHSA-qgw5-7j4f-fg97","summary":"Nuclei: Local File Read via Workflow File-Protocol Gate Bypass","details":"A vulnerability in Nuclei's workflow template loader allows `file:` protocol templates to execute without the `-file` flag, bypassing a security gate that is meant to prevent local file reads on the scanner host.\n\n**Affected Component**\n\nThe issue is in the workflow template loading path. The main template loader enforces the `-file` gate for file-protocol templates, but the workflow loader did not apply the same check when resolving templates referenced by a workflow.\n\n**Description**\n\nNuclei disables file-protocol templates by default because they read local files from the host running the scanner. Operators must explicitly enable them with the `-file` flag. When a workflow references a file-protocol template, the workflow loader accepted and executed that template without verifying that `-file` was enabled.\n\nBecause workflows run unsigned by default, an untrusted workflow could load and execute a file-protocol template and read local files from the scan target path, even though the operator had not enabled file templates.\n\n\u003e [!NOTE]\nFile-protocol templates are disabled by default. This issue only affects users who run workflows from untrusted sources without having explicitly enabled `-file`.\n\n**Affected Users**\n\n- **CLI users** running workflows (`-w`) that reference file-protocol templates from untrusted or third-party sources.\n- **SDK users** who integrate Nuclei into platforms where end users can supply workflow files and rely on the default `-file` restriction to block local file access.\n\n**Patches**\n\n- The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended.\n- Fix reference: https://github.com/projectdiscovery/nuclei/pull/7489\n\n**Mitigation**\n\nUpgrade to Nuclei v3.10.0, where template execution requirements (including the `-file` gate) are enforced consistently across the main loader, workflow parsing, and request compilation paths.\n\nIn the meantime, avoid running workflows from unverified sources.\n\n**Workarounds**\n\nIf upgrading is not an option, do not run untrusted workflow files. There is no configuration flag that mitigates this bypass on affected versions.\n\n**Acknowledgments**\n\nThanks to @daffainfo for reporting this issue.","aliases":["CVE-2026-76804","GO-2026-6574"],"modified":"2026-10-01T20:55:47.101258667Z","published":"2026-09-22T20:37:21Z","database_specific":{"cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:37:21Z","nvd_published_at":"2026-09-22T17:17:24Z"},"references":[{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-qgw5-7j4f-fg97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76804"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/pull/7489"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/commit/638be4481d27f1bbf90f971bbf6e3023777f2089"},{"type":"PACKAGE","url":"https://github.com/projectdiscovery/nuclei"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0"}],"affected":[{"package":{"name":"github.com/projectdiscovery/nuclei/v3","ecosystem":"Go","purl":"pkg:golang/github.com/projectdiscovery/nuclei/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-qgw5-7j4f-fg97/GHSA-qgw5-7j4f-fg97.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}