HIGH 8.6 GitHub
CVE-2026-76819
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.
**Affected Component**
The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol (`pkg/js/`). An out-of-bounds heap write in the engine can be exploited to achieve native code execution during template evaluation.
**Description**
Nuclei uses the Goja engine to execute `javascrip
Affected Products
- go/github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.10.0
References
- https://github.com/advisories/GHSA-vxg7-f2jj-jmqm
- https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm
- https://nvd.nist.gov/vuln/detail/CVE-2026-76819
- https://github.com/projectdiscovery/nuclei/pull/7467
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-22 via GitHub. Affected: go/github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.10.0.
vulnfeed aggregates 13417 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.