{"id":"CVE-2026-41282","aliases":["GHSA-jm34-66cf-qpvr","CVE-2026-41645","GO-2026-5473"],"title":"Nuclei: Environment variable disclosure via Response-Derived DSL Expressions","summary":"Nuclei: Environment variable disclosure via Response-Derived DSL Expressions","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","vendor":"projectdiscovery","product":"github.com/projectdiscovery/nuclei/v3","ecosystem":"go","affected":["github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.8.0"],"patched":["github.com/projectdiscovery/nuclei/v3 3.8.0"],"published":"2026-04-22","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jm34-66cf-qpvr","references":[{"url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41645"},{"url":"https://github.com/projectdiscovery/nuclei/pull/7221"},{"url":"https://github.com/projectdiscovery/nuclei/pull/7321"},{"url":"https://github.com/projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb"},{"url":"https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3"},{"url":"https://github.com/projectdiscovery/nuclei"},{"url":"https://github.com/projectdiscovery/nuclei/releases/tag/v3.8.0"}],"tags":["osv","go"],"epss":0.0025,"epssPercentile":0.16651,"ingestedAt":"2026-07-09T18:56:36.585Z","slug":"CVE-2026-41282","body":"## Overview\n\nA vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the `-env-vars` / `-ev` option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk.\n\n**Affected Component**\n\nThe issue lives in `expressions.Evaluate()` at `pkg/protocols/common/expressions/` and in the unresolved-variable validation path (`hasLiteralsOnly()`).\n\n**Description**\n\n`expressions.Evaluate()` replaces placeholders first, then scans the substituted output for expressions. Because of this two-pass approach, response-derived values (including extractor output and response body content) can be reinterpreted as DSL/helper syntax on the second pass.\n\nWhen `-env-vars` (`-ev`) is enabled, environment variables get merged into the template variable map. A malicious target can return response data containing expressions like `{{env_var_name}}` which, when reused in a subsequent template request, resolve to actual environment variable values. This can expose sensitive host data like API keys, credentials, and tokens.\n\nWithout `-ev` enabled (the default), injected DSL expressions may still trigger helper functions such as `{{md5(\"test\")}}`, but this has no meaningful security impact beyond unexpected behavior.\n\nThere is also a separate issue in `hasLiteralsOnly()`: it was evaluating helper expressions while deciding whether `{{...}}` contained unresolved variables, which caused validation logic to run side-effectful helpers even when the final request kept the value as a literal.\n\n> [!NOTE]\nThe `-env-vars` / `-ev` option is off by default. Users who have not explicitly turned it on are not affected by the information disclosure aspect of this vulnerability.\n\n**Affected Users**\n\n- **CLI users** running multi-step templates (with extractors or flow-based request chaining) that reuse response-derived values against untrusted or attacker-controlled targets, with the `-ev` flag enabled.\n- **SDK users** who have integrated Nuclei into platforms where `EnvironmentVariables` is set to `true` and scan targets are not fully trusted.\n\n**Patches**\n\n- The vulnerability is fixed in Nuclei v3.8.0. Upgrading to this version is strongly recommended.\n- Relevant fix references: #7221, #7321.\n\n**Mitigation**\n\nUpgrade to Nuclei v3.8.0. The updated evaluation logic now collects expressions from the original template text before placeholder substitution and only evaluates those template-authored expressions.\n\nIf you have `-ev` enabled, disable it when scanning untrusted targets to avoid environment variable disclosure.\n\n**Workarounds**\n\nIf upgrading is not an option right now, make sure `-env-vars` / `-ev` is not enabled when running multi-step templates against untrusted targets.\n\n**Acknowledgments**\n\nNuclei thanks @gnuletik for reporting this issue through responsible disclosure via security@projectdiscovery.io\n\n## Affected packages\n\n- `github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.8.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/projectdiscovery/nuclei/v3 3.8.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}