ProjectDiscovery contributors submitted new Nuclei detection content to expand coverage for two separate security issues: CVE-2021-42392 and an unauthenticated exposure condition affecting PhotoPrism. Pull request #15734, opened by maciejklimek, proposes adding a template for CVE-2021-42392, while pull request #15766, opened by pussycat0x, adds photoprism-unauth-exposure.yaml to identify publicly accessible PhotoPrism instances without authentication.
Both submissions were presented as defensive scanning updates in the projectdiscovery/nuclei-templates repository and included standard validation notes stating they were tested against vulnerable and patched targets. Repository automation requested reviewer attention, and the PhotoPrism template was marked ready to merge, while the CVE-2021-42392 template remained open pending review; neither reference indicated an active intrusion campaign or confirmed breach tied to the detections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A pull request was opened in the projectdiscovery/nuclei-templates repository to add photoprism-unauth-exposure.yaml for detecting unauthenticated exposure in PhotoPrism. The change was presented as defensive detection content and marked ready for review.
A pull request was opened in the projectdiscovery/nuclei-templates repository to add a Nuclei detection template for CVE-2021-42392. The submission stated it was validated against vulnerable and patched hosts and awaited review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.