CVE-2026-41282: Code Injection
Published Apr 20, 2026
·Updated
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
Affected Software
2 affected components
ProjectDiscovery nuclei<3.8.0
ProjectDiscovery Nuclei Go>=3.0.0<3.8.0
Remediation
Event History
Apr 20, 2026
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 7, 58279
Event
via NVD·12:14 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-41282?
CVE-2026-41282 is classified as a moderate severity vulnerability due to the potential for DSL expression injection.
2
How do I fix CVE-2026-41282?
To fix CVE-2026-41282, update ProjectDiscovery Nuclei to version 3.8.0 or later.
3
What versions of ProjectDiscovery Nuclei are affected by CVE-2026-41282?
CVE-2026-41282 affects ProjectDiscovery Nuclei versions prior to 3.8.0.
4
What specific feature is vulnerable in CVE-2026-41282?
CVE-2026-41282 involves the -env-vars functionality in multi-step templates when used against untrusted targets.
5
Is CVE-2026-41282 a default configuration issue?
No, CVE-2026-41282 affects specific configurations of Nuclei that are not set as the default.