PT-2026-96834 · Nuclei · Nuclei

CVE-2026-76803

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nuclei versions 3.0.0 through 3.9.9
Description The nuclei/mysql JavaScript library fails to enforce the local-file sandbox when a JavaScript template uses the allowAllFiles MySQL DSN option. This allows an untrusted javascript: template scanning a MySQL-compatible endpoint to trigger LOAD DATA LOCAL INFILE requests for arbitrary paths. Consequently, the MySQL client reads the requested files and returns their contents to the server, bypassing the -allow-local-file-access restriction. This issue affects both CLI and SDK deployments that accept untrusted templates, as JavaScript templates can run unsigned and without the -code flag on affected versions.
Recommendations Update to version 3.10.0. Avoid running JavaScript templates from unverified sources, especially against untrusted database endpoints.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76803
GHSA-XHMX-W2J4-RW3Q

Affected Products

Nuclei