<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:51:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-309147</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309147</link>
      <description>EUVD-2026-309147</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309147</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41646</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41646</link>
      <description>&lt;p&gt;Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei&amp;#39;s JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei&amp;#39;s JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41646</guid>
    </item>
    <item>
      <title>GHSA-29rg-wmcw-hpf4 — Nuclei: Local File Read via require() Module Loader Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-29rg-wmcw-hpf4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectdiscovery/nuclei/v3&lt;/p&gt;
&lt;p&gt;A vulnerability in Nuclei&amp;#39;s JavaScript protocol runtime allows JavaScript templates to read local `.js` and `.json` files through the `require()` function, bypassing the default local file access restriction.&lt;/p&gt;
&lt;p&gt;**Affected Component**&lt;/p&gt;
&lt;p&gt;The issue is in the JavaScript runtime&amp;#39;s module loading system. The goja `require()` function used a default host filesystem loader without routing through the `allow-local-file-access` check.&lt;/p&gt;
&lt;p&gt;**Description**&lt;/p&gt;
&lt;p&gt;The goja require() function in Nuclei&amp;#39;s JavaScript protocol runtime used the default host filesystem loader, which allowed JavaScript templates to import .js and .json files from anywhere on the host filesystem, ignoring the allow-local-file-access (-lfa) option that controls file access outside the template directory.&lt;/p&gt;
&lt;p&gt;The impact is limited to `.js` and `.json` files, as goja&amp;#39;s module loader only resolves those extensions. That said, this is still enough to expose sensitive data stored in JSON configuration files like `package.json`, credential stores, or cloud configuration files sitting on the host filesystem.&lt;/p&gt;
&lt;p&gt;**Affected Users**&lt;/p&gt;
&lt;p&gt;- **CLI users** running untrusted or third-party JavaScript templates.
- **SDK users** who have integrated Nuclei into platforms where end-users can supply JavaScript templates, especially when relying on the default file access restriction to limit filesystem reads.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
The `require()` module loader only resolves `.js` and `.json` files. Other file types cannot be read through this vector.&lt;/p&gt;
&lt;p&gt;**Patches*…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectdiscovery/nuclei/v3&lt;/p&gt;
&lt;p&gt;A vulnerability in Nuclei&amp;#39;s JavaScript protocol runtime allows JavaScript templates to read local `.js` and `.json` files through the `require()` function, bypassing the default local file access restriction.&lt;/p&gt;
&lt;p&gt;**Affected Component**&lt;/p&gt;
&lt;p&gt;The issue is in the JavaScript runtime&amp;#39;s module loading system. The goja `require()` function used a default host filesystem loader without routing through the `allow-local-file-access` check.&lt;/p&gt;
&lt;p&gt;**Description**&lt;/p&gt;
&lt;p&gt;The goja require() function in Nuclei&amp;#39;s JavaScript protocol runtime used the default host filesystem loader, which allowed JavaScript templates to import .js and .json files from anywhere on the host filesystem, ignoring the allow-local-file-access (-lfa) option that controls file access outside the template directory.&lt;/p&gt;
&lt;p&gt;The impact is limited to `.js` and `.json` files, as goja&amp;#39;s module loader only resolves those extensions. That said, this is still enough to expose sensitive data stored in JSON configuration files like `package.json`, credential stores, or cloud configuration files sitting on the host filesystem.&lt;/p&gt;
&lt;p&gt;**Affected Users**&lt;/p&gt;
&lt;p&gt;- **CLI users** running untrusted or third-party JavaScript templates.
- **SDK users** who have integrated Nuclei into platforms where end-users can supply JavaScript templates, especially when relying on the default file access restriction to limit filesystem reads.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
The `require()` module loader only resolves `.js` and `.json` files. Other file types cannot be read through this vector.&lt;/p&gt;
&lt;p&gt;**Patches*…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-29rg-wmcw-hpf4</guid>
    </item>
  </channel>
</rss>
