CVE-2026-76819: Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

Published Sep 22, 2026
·
Updated

A vulnerability in the Goja JavaScript engine used by Nuclei's javascript: protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.

Affected Component

The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (pkg/js/). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.

Description

Nuclei uses the Goja engine to execute javascript: protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei.

Because javascript: templates execute without the -code flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template's init section, which runs during template initialization before other security checks complete.

[!NOTE] JavaScript templates do not require the -code flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth.

Affected Users

- CLI users running untrusted or third-party javascript: templates. - SDK users who integrate Nuclei into platforms where end users can supply JavaScript templates.

Patches

- The vulnerability is fixed in Nuclei v3.10.0 by updating the Goja dependency. Upgrading is strongly recommended. - Fix reference: https://github.com/projectdiscovery/nuclei/pull/7467 - Additional hardening in v3.11.0 requires cryptographic signatures for JavaScript templates: https://github.com/projectdiscovery/nuclei/pull/7514

Mitigation

Upgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid signatures.

In the meantime, avoid running JavaScript templates from unverified sources.

Workarounds

If upgrading is not an option, do not run untrusted JavaScript templates. There is no configuration flag that mitigates native code execution on affected versions.

Acknowledgments

Thanks to Dylan Pindur (@dpindur) and Adam Kues (@akues-an) of the Assetnote security research team for reporting this issue through responsible disclosure via security@projectdiscovery.io.

Other sources

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0.

MITRE

Rejected reason: Further research determined the issue results from a dependency.

NVD

Affected Software

2 affected componentsFixes available
ProjectDiscovery nuclei>=3.0.0<3.10.0
go/github.com/projectdiscovery/nuclei/v3>=3.0.0<3.10.0
3.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/projectdiscovery/nuclei/v3 to a version that resolves this vulnerability.

    Fixed in 3.10.0
  2. Upgrade

    Upgrade Nuclei to a version that resolves this vulnerability.

    Fixed in 3.11.0
  3. Compensating control

    Do not run untrusted or unverified JavaScript templates if upgrading is not an option.

Event History

Sep 22, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
Description
Advisory Published
via GitHub·08:37 PM
Data Sourced
via GitHub·08:37 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are most exposed?

CLI and SDK deployments that accept third-party templates are exposed on affected versions, because unsigned JavaScript templates run by default. The vulnerable JavaScript runtime is used by the javascript: protocol under pkg/js/.

2

What does an attacker need to exploit this?

An attacker needs to get a malicious, untrusted JavaScript template evaluated by Nuclei. The template can trigger the issue during a normal scan, including from an init section executed during template initialization.

3

Is the -code flag required for exploitation?

No. JavaScript templates execute without the -code flag, so that flag does not prevent execution of a malicious JavaScript template on affected versions.

4

What should teams do if they cannot patch immediately?

Do not accept or run untrusted third-party JavaScript templates. Restrict template sources to trusted content until Nuclei can be updated.

5

How can I determine whether an installation is affected?

Installations running Nuclei from 3.0.0 through versions before 3.10.0 are affected if they evaluate JavaScript templates. Version 3.10.0 fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203