Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-41282

MEDIUM NVD
CVSS Score 4
Severity MEDIUM
Published Apr 20, 2026
Vendor unknown

Description

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

References