HIGH 8.6 GitHub

CVE-2026-76819

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates. **Affected Component** The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (`pkg/js/`). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation. **Description** Nuclei uses the Goja engine to execute `javascrip

Affected Products

References

Published: 2026-09-22 · Source: GitHub · Feed updated: 2026-09-22
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-22 via GitHub. Affected: go/github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.10.0.
vulnfeed aggregates 13417 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.