PT-2026-51143 · Nuxt · Nuxt

·

CVE-2026-56317

·

Published

2026-06-16

·

Updated

2026-06-24

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nuxt versions prior to 4.4.7 Nuxt versions prior to 3.21.7
Description A cross-site scripting issue exists in the NoScript component, which writes slot content to innerHTML without proper escaping. This allows attackers to inject malicious scripts via untrusted data in NoScript slots, such as route.query parameters. These scripts execute in the document context when the noscript tag is implicitly closed by script tags.
Recommendations Update to version 4.4.7 or later. Update to version 3.21.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56317
GHSA-M3Q2-P4FW-W38M
GHSA-XPPM-JMW6-FHMF

Affected Products

Nuxt