5.5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Description
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.
Basic Information
ID
CVE-2026-41646
Source
GitHub_M
Published
May 8, 2026 at 03:14
Affected Product
Vendor
projectdiscovery
Product
nuclei
Version
>= 3.0.0, < 3.8.0
Affected Versions
projectdiscovery nuclei >= 3.0.0, < 3.8.0