PT-2026-96835 · Nuclei · Nuclei

CVE-2026-76804

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nuclei versions 3.0.0 through 3.9.9
Description The workflow template loading path fails to enforce the -file capability gate when resolving templates using the file: protocol referenced by a workflow. This allows an untrusted, unsigned workflow to load a file-protocol template and read local files from the scanner host, bypassing the default security restriction that requires the -file flag to be explicitly enabled. This issue affects CLI users executing workflows via the -w flag and SDK integrations that accept end-user workflows while relying on default file-access restrictions.
Recommendations Update to version 3.10.0. Avoid running workflows from unverified sources.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76804
GHSA-QGW5-7J4F-FG97

Affected Products

Nuclei