
CVE-2026-41282 ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the defa… https://www.cve.org/CVERecord?id=CVE-2026-41282
Post summary
The text announces CVE-2026-41282, a vulnerability in ProjectDiscovery Nuclei that permits DSL expression injection via the -env-vars option, potentially impacting multi‑step templates against untrusted targets.

