PT-2026-51143 · Nuxt · Nuxt
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nuxt versions prior to 4.4.7
Nuxt versions prior to 3.21.7
Description
A cross-site scripting issue exists in the NoScript component, which writes slot content to innerHTML without proper escaping. This allows attackers to inject malicious scripts via untrusted data in NoScript slots, such as
route.query parameters. These scripts execute in the document context when the noscript tag is implicitly closed by script tags.Recommendations
Update to version 4.4.7 or later.
Update to version 3.21.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuxt