{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nuclei--3.11.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-92718"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nuclei (\u003c 3.11.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ProjectDiscovery"],"content_html":"\u003cp\u003eNuclei versions prior to 3.11.1 contain a critical flaw in the template signature verification process. The application attempts to optimize performance by caching the results of signature verification based solely on the file modification timestamp (mtime) of the template rather than utilizing cryptographic checksums. An attacker who has gained local access to the system can replace a legitimate, previously verified template with an unsigned, malicious variant. By restoring the original modification timestamp of the file, the attacker forces the Nuclei engine to treat the malicious content as validly signed. When Nuclei executes the tampered template, it may perform unauthorized actions, including the execution of arbitrary operating system commands, depending on the capabilities defined in the malicious template. This vulnerability is particularly impactful in automated pipeline environments where Nuclei is trusted to perform security scans.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized file system access to the directory containing Nuclei templates.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a legitimate template that has already been verified and cached by Nuclei.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the template file to include malicious instructions or payloads capable of OS command execution.\u003c/li\u003e\n\u003cli\u003eAttacker updates the file modification timestamp of the malicious template to match the original timestamp of the legitimate file.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a scan or waits for the next scheduled execution of the Nuclei scanner.\u003c/li\u003e\n\u003cli\u003eNuclei performs a cache lookup, confirms the modification time matches the cached state, and skips re-verification.\u003c/li\u003e\n\u003cli\u003eThe Nuclei engine executes the tampered template as a trusted entity.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: arbitrary code execution on the host running the Nuclei scanner.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary command execution under the privileges of the Nuclei process. This represents a significant risk for organizations relying on Nuclei in CI/CD pipelines, automated security orchestration, or local security tooling. If exploited, an attacker could escalate local access to full system control or pivot further into the internal network from the scanning host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Nuclei to version 3.11.1 or later to implement secure cryptographic template verification.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on directories storing Nuclei templates to alert on unexpected file modifications.\u003c/li\u003e\n\u003cli\u003eRestrict file system permissions for the directory containing Nuclei templates, ensuring only the service account running the scanner has write access.\u003c/li\u003e\n\u003cli\u003eConduct an audit of existing templates to identify unauthorized modifications.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T19:52:07Z","date_published":"2026-09-16T19:52:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nuclei-template-bypass/","summary":"Nuclei versions before 3.11.1 are vulnerable to template signature bypass due to reliance on file modification timestamps for cache validation, allowing attackers to inject malicious templates.","title":"Nuclei Template Signature Verification Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-nuclei-template-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Nuclei (\u003c 3.11.1)","version":"https://jsonfeed.org/version/1.1"}