Kestrel
대시보드로 돌아가기
CVE-2026-76819HIGH· 8.6NVDGHSA대응게시일: 2026. 09. 22.수정일: 2026. 09. 22.

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
8.6high

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한차기 업그레이드 시CISA SSVC 기준

별도 긴급 패치 불필요 — 정기 시스템 업그레이드 주기에 맞춰 조치

완전 장악· KEV 미등재 · 자동화 어려움 · 완전 장악 · 내부 한정

CVSS 벡터 · 메트릭

악용 경로
공격 벡터로컬
공격 복잡도낮음
필요 권한불필요
사용자 상호작용필요
범위변경
영향
기밀성 영향높음
무결성 영향높음
가용성 영향높음
버전별 점수
CVSS 3.18.6HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

상세 설명

A vulnerability in the Goja JavaScript engine used by Nuclei's javascript: protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.

Affected Component

The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (pkg/js/). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.

Description

Nuclei uses the Goja engine to execute javascript: protocol templates. A memory safety vulnerability in Goja allows attacker-controlled JavaScript to corrupt heap memory and execute arbitrary native code on the host running Nuclei.

Because javascript: templates execute without the -code flag and unsigned JavaScript templates run by default, a malicious template from an untrusted source can trigger code execution during a normal scan. The vulnerability could also be reached through a template's init section, which runs during template initialization before other security checks complete.

[!NOTE]
JavaScript templates do not require the -code flag and are not subject to the code-template signing requirement on affected versions. Nuclei v3.11.0 adds a separate signing requirement for JavaScript templates as additional defense in depth.

Affected Users

  • CLI users running untrusted or third-party javascript: templates.
  • SDK users who integrate Nuclei into platforms where end users can supply JavaScript templates.

Patches

Mitigation

Upgrade to Nuclei v3.10.0 or later. For additional protection, upgrade to v3.11.0 where JavaScript templates also require valid signatures.

In the meantime, avoid running JavaScript templates from unverified sources.

Workarounds

If upgrading is not an option, do not run untrusted JavaScript templates. There is no configuration flag that mitigates native code execution on affected versions.

Acknowledgments

Thanks to Dylan Pindur (@dpindur) and Adam Kues (@akues-an) of the Assetnote security research team for reporting this issue through responsible disclosure via security@projectdiscovery.io.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.