CVE-2026-41282
EUVD-2026-2379520.04.2026, 08:16
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| projectdiscovery | nuclei | 3.0.0 ≤ 𝑥 < 3.8.0 |
𝑥
= Vulnerable software versions
References