Impact
Nuclei prior to version 3.11.1 caches template signatures and validates them only by checking file modification timestamps. This flaw lets an attacker with write access to the templates directory replace a verified template with malicious content, then set the original modification time to bypass the signature check. The engine then loads the tampered template and executes the embedded OS commands, giving the attacker full command execution on the host.
Affected Systems
The vulnerability affects the projectdiscovery:nuclei product in versions 3.7.0 through 3.11.0 inclusive. Any deployment that uses local templates from these versions and allows write access to the template directory is susceptible, particularly environments where templates are stored in a shared or unprotected location.
Risk and Exploitability
With a CVSS score of 7 the flaw is considered high severity, and the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been confirmed. Exploitation requires the attacker to have the ability to modify the template files and adjust their timestamps, after which the bypass enables arbitrary command execution on the system running Nuclei.
OpenCVE Enrichment