Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:* |
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectdiscovery
Projectdiscovery nuclei |
|
| Vendors & Products |
Projectdiscovery
Projectdiscovery nuclei |
Mon, 20 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Nuclei 3 Expression Injection via -env-vars |
Mon, 20 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration). | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T00:59:19.998Z
Reserved: 2026-04-20T07:10:29.549Z
Link: CVE-2026-41282
Updated: 2026-04-20T14:46:59.795Z
Status : Analyzed
Published: 2026-04-20T08:16:10.140
Modified: 2026-04-23T15:25:04.777
Link: CVE-2026-41282
No data.
OpenCVE Enrichment
Updated: 2026-04-20T09:30:03Z