๐Ÿ” CVE Alert

CVE-2026-56698

MEDIUM 6.1

Nuxt - Cross-Site Scripting via navigateTo open Option

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary scripts in the application's origin when user-controlled input is passed to navigateTo.

CWE CWE-79
Vendor nuxt
Product nuxt
Published Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for nuxt nuxt

Be the first to know when new medium vulnerabilities affecting nuxt nuxt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Nuxt / Nuxt
4.0.0 < 4.4.7
Nuxt / Nuxt
0 < 3.21.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nuxt/nuxt/security/advisories/GHSA-c9cv-mq2m-ppp3 github.com: https://github.com/nuxt/nuxt/commit/3394716d4a913cba904b028df5338f2aead50032 github.com: https://github.com/nuxt/nuxt/commit/62fc32eddf648b00a3890141e0235d2a222b024d vulncheck.com: https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-navigateto-open-option

Credits

๐Ÿ” alcls01111