---
id: CVE-2023-37896
aliases:
  - GHSA-2xx4-jj5v-6mff
  - GO-2023-1998
title: Nuclei Path Traversal vulnerability
summary: Nuclei Path Traversal vulnerability
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: projectdiscovery
product: github.com/projectdiscovery/nuclei/v2
ecosystem: go
affected:
  - github.com/projectdiscovery/nuclei/v2 < 2.9.9
  - github.com/projectdiscovery/nuclei < 2.9.9
patched:
  - github.com/projectdiscovery/nuclei/v2 2.9.9
  - github.com/projectdiscovery/nuclei 2.9.9
published: '2023-08-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:08.588771152Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2xx4-jj5v-6mff'
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-2xx4-jj5v-6mff
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-37896'
  - url: 'https://github.com/projectdiscovery/nuclei/pull/3927'
  - url: 'https://github.com/projectdiscovery/nuclei'
  - url: 'https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9'
tags:
  - osv
  - go
epss: 0.01048
epssPercentile: 0.62687
ingestedAt: '2026-09-12T03:13:01.747Z'
---

## Overview

## Overview

We have identified and addressed a security issue in the Nuclei project that affected users utilizing Nuclei as **Go code (SDK)** running **custom templates**. This issue did not affect CLI users. The problem was related to sanitization issues with payloads loading in `sandbox` mode.

## Details

In the previous versions, there was a potential risk with payloads loading in sandbox mode. The issue occurred due to relative paths not being converted to absolute paths before doing the check for `sandbox` flag allowing arbitrary files to be read on the filesystem in certain cases when using Nuclei from `Go` SDK implementation. 

This issue has been fixed in the latest release, v2.9.9. We have also enabled sandbox by default for filesystem loading. This can be optionally disabled if required.

The `-sandbox` option has been **deprecated** and is now divided into two new options: `-lfa` (allow local file access) which is disabled by default and `-lna` (restrict local network access) which can be optionally disabled by user. The `-lfa` allows file (payload) access anywhere on the system (disabling sandbox effectively), and `-lna` blocks connections to the local/private network.

## Affected Versions

This issue affected all versions of Nuclei prior to v2.9.9.

## Patches

We recommend all users upgrade to the latest version, [v2.9.9](https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9), which includes the security fix.

### References

- [patch](https://github.com/projectdiscovery/nuclei/pull/3927)
- [releases](https://github.com/projectdiscovery/nuclei/releases/tag/v2.9.9)

## Acknowledgments

We would like to thank **keomutchoiboi** who reported this issue to us via our security email, [security@projectdiscovery.io](mailto:security@projectdiscovery.io). We appreciate the responsible disclosure of this issue.

## Affected packages

- `github.com/projectdiscovery/nuclei/v2 < 2.9.9`
- `github.com/projectdiscovery/nuclei < 2.9.9`

## Remediation

Upgrade to a patched release:

- `github.com/projectdiscovery/nuclei/v2 2.9.9`
- `github.com/projectdiscovery/nuclei 2.9.9`
