PT-2026-97130 · Nuclei+1 · Nuclei+1
CVE-2026-76819
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nuclei versions 3.0.0 through 3.9.9
Description
An out-of-bounds heap write in the Goja JavaScript runtime embedded in the
javascript: protocol under pkg/js/ allows arbitrary native code execution on the host running the scanner. This occurs when evaluating untrusted JavaScript templates, including those containing a malicious init section that executes during initialization. Because JavaScript templates on affected versions run by default without requiring the -code flag or cryptographic signatures, CLI and SDK deployments that accept third-party templates are exposed.Recommendations
Upgrade to version 3.10.0.
Upgrade to version 3.11.0 to enable additional hardening that requires cryptographic signatures for JavaScript templates.
Avoid running JavaScript templates from unverified sources.
Fix
Memory Corruption
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goja
Nuclei