PT-2026-97130 · Nuclei+1 · Nuclei+1

CVE-2026-76819

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nuclei versions 3.0.0 through 3.9.9
Description An out-of-bounds heap write in the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ allows arbitrary native code execution on the host running the scanner. This occurs when evaluating untrusted JavaScript templates, including those containing a malicious init section that executes during initialization. Because JavaScript templates on affected versions run by default without requiring the -code flag or cryptographic signatures, CLI and SDK deployments that accept third-party templates are exposed.
Recommendations Upgrade to version 3.10.0. Upgrade to version 3.11.0 to enable additional hardening that requires cryptographic signatures for JavaScript templates. Avoid running JavaScript templates from unverified sources.

Fix

Memory Corruption

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76819
GHSA-VXG7-F2JJ-JMQM

Affected Products

Goja
Nuclei