v3.11.1

2026-08-09T08:51:30Z53b5c3306be84adbe78a5775b4911413346bfb17d6552faa4368f7f4e3e74250
CVE-2026-41646JavaScript templatesProjectDiscovery Nucleicapability gatingcode executionlocal file accessreleasesandboxingsecurity fixsecurity hardeningtemplate signing

What happened

ProjectDiscovery Nuclei releases v3.8.0–v3.11.1 include multiple security hardening changes. Nuclei v3.8.0 fixes CVE-2026-41646 involving local-file access enforcement in JavaScript require handling and restricts evaluation of expressions. v3.10.0 adds capability gating, protects file access, and validates code-template signatures, addressing GHSA-qgw5-7j4f-fg97 and GHSA-xhmx-w2j4-rw3q. v3.11.0 requires digital signatures for custom JavaScript templates, reducing the risk of executing untrusted code. Users should upgrade and sign or replace affected custom templates.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
projectdiscovery_nuclei_releases
Record identifier
53b5c3306be84adbe78a5775b4911413346bfb17d6552faa4368f7f4e3e74250
Enrichment time
2026-08-09T08:51:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v3.11.1 · Baitaphish