7.3
CVE-2026-92718
- EPSS 0.11%
- Veröffentlicht 16.09.2026 17:31:38
- Zuletzt bearbeitet 24.09.2026 21:04:40
- Erkennungen
Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerprojectdiscovery
≫
Produkt
nuclei
Default Statusunaffected
Version
3.7.0
Version <
3.11.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.014 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.3 | 1.3 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
https://github.com/projectdiscovery/nuclei/issues/7663
https://github.com/projectdiscovery/nuclei
https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/templates/compile.go#L610-L624
https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/catalog/index/metadata.go#L78-L84
https://github.com/projectdiscovery/nuclei/commit/9de96e4dda5a03da963b9ae6582f03ea55791a76
https://www.vulncheck.com/advisories/nuclei-from-3.7.0-before-3.11.1-template-signature-bypass-via-modification-time-only-cache