CVE-2024-27920

7.4 HIGH
Published: March 15, 2024 Modified: December 05, 2025

Description

projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates through workflows. This vulnerability specifically affects users utilizing custom workflows, potentially allowing the execution of malicious code on the user's system. This advisory outlines the impacted users, provides details on the security patch, and suggests mitigation strategies. The vulnerability is addressed in Nuclei v3.2.0. Users are strongly recommended to update to this version to mitigate the security risk. Users should refrain from using custom workflows if unable to upgrade immediately. Only trusted, verified workflows should be executed.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://docs.projectdiscovery.io/templates/protocols/code
Source: security-advisories@github.com
Technical Description
https://docs.projectdiscovery.io/templates/reference/template-signing
Source: security-advisories@github.com
Technical Description
https://docs.projectdiscovery.io/templates/workflows/overview
Source: security-advisories@github.com
Technical Description
https://github.com/projectdiscovery/nuclei/pull/4822
Source: security-advisories@github.com
Issue Tracking
https://docs.projectdiscovery.io/templates/protocols/code
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
https://docs.projectdiscovery.io/templates/reference/template-signing
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
https://docs.projectdiscovery.io/templates/workflows/overview
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
https://github.com/projectdiscovery/nuclei/pull/4822
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-w5wx-6g2r-r78q
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

10 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.4 / 10.0
EPSS (Exploit Probability)
0.4%
61th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

projectdiscovery