CVE-2026-41282 Details
Description
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
A vulnerability allowing DSL expression injection has been identified in ProjectDiscovery Nuclei versions 3.0.0 prior to 3.8.0. This issue arises in the expression evaluation engine, where response-derived values can be reinterpreted as DSL syntax, potentially leading to the execution of unintended commands or functions. The vulnerability is particularly concerning when the '-env-vars' option is enabled, as it can expose sensitive environment variables from the host.
Upgrade to ProjectDiscovery Nuclei version 3.8.0 or later, where this vulnerability has been fixed. If an immediate upgrade is not possible, avoid using the '-env-vars' option when scanning untrusted targets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| projectdiscovery nuclei | >= 3.0.0, < 3.8.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |