{"id":"GHSA-vxg7-f2jj-jmqm","summary":"Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability","details":"A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.\n\n**Affected Component**\n\nThe issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (`pkg/js/`). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.\n\n**Description**\n\nNuclei uses the Goja engine to execute `javascript:` protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei.\n\nBecause `javascript:` templates execute without the `-code` flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template's `init` section, which runs during template initialization before other security checks complete.\n\n\u003e [!NOTE]\nJavaScript templates do not require the `-code` flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth.\n\n**Affected Users**\n\n- **CLI users** running untrusted or third-party `javascript:` templates.\n- **SDK users** who integrate Nuclei into platforms where end users can supply JavaScript templates.\n\n**Patches**\n\n- The vulnerability is fixed in Nuclei v3.10.0 by updating the Goja dependency. Upgrading is strongly recommended.\n- Fix reference: https://github.com/projectdiscovery/nuclei/pull/7467\n- Additional hardening in v3.11.0 requires cryptographic signatures for JavaScript templates: https://github.com/projectdiscovery/nuclei/pull/7514\n\n**Mitigation**\n\nUpgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid signatures.\n\nIn the meantime, avoid running JavaScript templates from unverified sources.\n\n**Workarounds**\n\nIf upgrading is not an option, do not run untrusted JavaScript templates. There is no configuration flag that mitigates native code execution on affected versions.\n\n**Acknowledgments**\n\nThanks to Dylan Pindur ([@dpindur](https://github.com/dpindur)) and Adam Kues ([@akues-an](https://github.com/akues-an)) of the Assetnote security research team for reporting this issue through responsible disclosure via security@projectdiscovery.io.","aliases":["CVE-2026-76819","GO-2026-6575"],"modified":"2026-10-01T20:55:44.790779575Z","published":"2026-09-22T20:37:13Z","database_specific":{"nvd_published_at":"2026-09-22T17:17:25Z","cwe_ids":["CWE-787","CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:37:13Z"},"references":[{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76819"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/pull/7467"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/pull/7514"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/commit/1fe6025b966cbb95ed4d9f40abfb629b6cbd27b2"},{"type":"PACKAGE","url":"https://github.com/projectdiscovery/nuclei"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0"}],"affected":[{"package":{"name":"github.com/projectdiscovery/nuclei/v3","ecosystem":"Go","purl":"pkg:golang/github.com/projectdiscovery/nuclei/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vxg7-f2jj-jmqm/GHSA-vxg7-f2jj-jmqm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}