CVE Feed

    Dashboard / CVE / CVE-2024-40641

    CVE-2024-40641

    Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nuclei and allow users to edit and execute workflow files. In this case, users can execute arbitrary commands. (Although, as far as I know, most web applications use -t to execute). This issue has been addressed in version 3.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:Jul 17, 2024
    Last Modified:Apr 15, 2026
    EPS:Jul 17, 2024
    EPSS Score:0.00048
    CVSS Score:7.4

    Affected Products

    Vendor
    Projectdiscovery
    Product
    Nuclei

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High