PT-2026-34612 · Nuclei · Nuclei

·

CVE-2026-41645

·

Published

2026-04-22

·

Updated

2026-07-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nuclei versions 3.0.0 through 3.7.9
Description A flaw in the expression evaluation engine allows a malicious target server to inject and execute supported Domain Specific Language (DSL) expressions. This occurs when HTTP response data containing helper or function syntax is reused by multi-step templates. The expressions.Evaluate() function replaces placeholders first and then scans the output for expressions; this two-pass process allows response-derived values to be reinterpreted as DSL syntax. Additionally, the hasLiteralsOnly() function evaluated helper expressions during unresolved-variable validation, causing side-effectful helpers to run. If the -env-vars or -ev option is enabled, an attacker can return response data containing expressions like {{env var name}} to expose sensitive host environment variables such as API keys, credentials, and tokens.
Recommendations Update to version 3.8.0. Disable the -env-vars or -ev option when scanning untrusted targets.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41645
GHSA-JM34-66CF-QPVR
GO-2026-5473
OPENSUSE-SU-2026:21483-1

Affected Products

Nuclei