PT-2026-96836 · Nuclei · Nuclei
CVE-2026-76805
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nuclei versions 3.0.0 through 3.9.9
Description
In DAST and fuzz modes, the payload path in
pkg/fuzz/parts.go can evaluate substituted runtime data multiple times. This occurs when a multi-step template captures response content using an internal: true extractor in one protocol step and reuses it in a subsequent fuzz step, causing the captured content to be reinterpreted as template syntax. If the -env-vars (or -ev) option is enabled, a malicious target can return marker-shaped content that resolves against the template variable map, leading to the disclosure of scanner-host environment variables such as API keys, credentials, or tokens.Recommendations
Update Nuclei to version 3.10.0.
Disable the
-env-vars or -ev option when scanning untrusted targets.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuclei