{"id":"CVE-2023-37896","aliases":["GHSA-2xx4-jj5v-6mff","GO-2023-1998"],"title":"Nuclei Path Traversal vulnerability","summary":"Nuclei Path Traversal vulnerability","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"projectdiscovery","product":"github.com/projectdiscovery/nuclei/v2","ecosystem":"go","affected":["github.com/projectdiscovery/nuclei/v2 < 2.9.9","github.com/projectdiscovery/nuclei < 2.9.9"],"patched":["github.com/projectdiscovery/nuclei/v2 2.9.9","github.com/projectdiscovery/nuclei 2.9.9"],"published":"2023-08-04","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:08.588771152Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-2xx4-jj5v-6mff","references":[{"url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-2xx4-jj5v-6mff"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37896"},{"url":"https://github.com/projectdiscovery/nuclei/pull/3927"},{"url":"https://github.com/projectdiscovery/nuclei"},{"url":"https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9"}],"tags":["osv","go"],"epss":0.01048,"epssPercentile":0.62745,"ingestedAt":"2026-09-12T03:13:01.747Z","slug":"CVE-2023-37896","body":"## Overview\n\n## Overview\n\nWe have identified and addressed a security issue in the Nuclei project that affected users utilizing Nuclei as **Go code (SDK)** running **custom templates**. This issue did not affect CLI users. The problem was related to sanitization issues with payloads loading in `sandbox` mode.\n\n## Details\n\nIn the previous versions, there was a potential risk with payloads loading in sandbox mode. The issue occurred due to relative paths not being converted to absolute paths before doing the check for `sandbox` flag allowing arbitrary files to be read on the filesystem in certain cases when using Nuclei from `Go` SDK implementation. \n\nThis issue has been fixed in the latest release, v2.9.9. We have also enabled sandbox by default for filesystem loading. This can be optionally disabled if required.\n\nThe `-sandbox` option has been **deprecated** and is now divided into two new options: `-lfa` (allow local file access) which is disabled by default and `-lna` (restrict local network access) which can be optionally disabled by user. The `-lfa` allows file (payload) access anywhere on the system (disabling sandbox effectively), and `-lna` blocks connections to the local/private network.\n\n## Affected Versions\n\nThis issue affected all versions of Nuclei prior to v2.9.9.\n\n## Patches\n\nWe recommend all users upgrade to the latest version, [v2.9.9](https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9), which includes the security fix.\n\n### References\n\n- [patch](https://github.com/projectdiscovery/nuclei/pull/3927)\n- [releases](https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9)\n\n## Acknowledgments\n\nWe would like to thank **keomutchoiboi** who reported this issue to us via our security email, [security@projectdiscovery.io](mailto:security@projectdiscovery.io). We appreciate the responsible disclosure of this issue.\n\n## Affected packages\n\n- `github.com/projectdiscovery/nuclei/v2 < 2.9.9`\n- `github.com/projectdiscovery/nuclei < 2.9.9`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/projectdiscovery/nuclei/v2 2.9.9`\n- `github.com/projectdiscovery/nuclei 2.9.9`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}