๐Ÿ” CVE Alert

CVE-2026-56326

MEDIUM 6.1

Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host checks using path-normalization techniques to redirect users to attacker-controlled sites via the Location header or meta-refresh, enabling phishing and OAuth authorization-code theft.

CWE CWE-601
Vendor nuxt
Product nuxt
Published Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for nuxt nuxt

Be the first to know when new medium vulnerabilities affecting nuxt nuxt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Nuxt / Nuxt
4.0.0 < 4.4.7
Nuxt / Nuxt
0 < 3.21.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nuxt/nuxt/security/advisories/GHSA-c9cv-mq2m-ppp3 github.com: https://github.com/nuxt/nuxt/commit/2cce6fb02e621196d56df92e05594e07469b5a6d github.com: https://github.com/nuxt/nuxt/commit/1f2dd5e78c77576437138e97671965573c232835 vulncheck.com: https://www.vulncheck.com/advisories/nuxt-server-side-open-redirect-via-path-normalization-bypass-in-navigateto

Credits

๐Ÿ” alcls01111