CVE-2024-27920 is a high-severity vulnerability in projectdiscovery/nuclei v3, allowing for the execution of unsigned code templates through custom workflows. This local attack, requiring user interaction, could lead to high confidentiality and integrity impacts by executing malicious code on the user's system. The vulnerability is patched in Nuclei v3.2.0, and users are advised to update immediately or avoid custom workflows from untrusted sources. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.2.0CPE matchmatch criteria | cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.