CVE-2026-41282
EUVD-2026-2379520.04.2026, 08:16
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| projectdiscovery | nuclei | 3.0.0 ≤ 𝑥 < 3.8.0 | CNA |
References