NIXPKGS-2026-1198
GitHub issue
published on
Permalink
CVE-2026-41282
4.0 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
2 packages
- nuclei-templates
- nucleiparser
- @LeSuisse accepted
- @LeSuisse published on GitHub
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This …
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
References
Ignored references (1)
Affected products
Nuclei
- <3.8.0
Matching in nixpkgs
Ignored packages (2)
pkgs.nucleiparser
Nuclei output parser for CLI
Package maintainers
-
@Misaka13514 Misaka13514 <Misaka13514@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>