v3.11.1
2026-08-09T08:51:30Z•53b5c3306be84adbe78a5775b4911413346bfb17d6552faa4368f7f4e3e74250
CVE-2026-41646JavaScript templatesProjectDiscovery Nucleicapability gatingcode executionlocal file accessreleasesandboxingsecurity fixsecurity hardeningtemplate signing
What happened
ProjectDiscovery Nuclei releases v3.8.0–v3.11.1 include multiple security hardening changes. Nuclei v3.8.0 fixes CVE-2026-41646 involving local-file access enforcement in JavaScript require handling and restricts evaluation of expressions. v3.10.0 adds capability gating, protects file access, and validates code-template signatures, addressing GHSA-qgw5-7j4f-fg97 and GHSA-xhmx-w2j4-rw3q. v3.11.0 requires digital signatures for custom JavaScript templates, reducing the risk of executing untrusted code. Users should upgrade and sign or replace affected custom templates.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- projectdiscovery_nuclei_releases
- Record identifier
- 53b5c3306be84adbe78a5775b4911413346bfb17d6552faa4368f7f4e3e74250
- Enrichment time
- 2026-08-09T08:51:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.