PT-2026-96835 · Nuclei · Nuclei
CVE-2026-76804
·
Published
2026-09-22
·
Updated
2026-09-28
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nuclei versions 3.0.0 through 3.9.9
Description
The workflow template loading path fails to enforce the
-file capability gate when resolving templates using the file: protocol referenced by a workflow. This allows an untrusted, unsigned workflow to load a file-protocol template and read local files from the scanner host, bypassing the default security restriction that requires the -file flag to be explicitly enabled. This issue affects CLI users executing workflows via the -w flag and SDK integrations that accept end-user workflows while relying on default file-access restrictions.Recommendations
Update to version 3.10.0.
Avoid running workflows from unverified sources.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuclei