PT-2026-51417 · Nuxt · Nuxt

·

CVE-2026-56698

·

Published

2026-06-16

·

Updated

2026-06-23

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nuxt versions 3.x prior to 3.21.7 Nuxt versions 4.0.0 through 4.4.6
Description Nuxt fails to validate script-capable URLs in the navigateTo open option, which allows for client-side script execution. When user-controlled input is passed to navigateTo, attackers can provide javascript: URLs through the open parameter to execute arbitrary scripts within the application's origin.
Recommendations Update versions 3.x to 3.21.7 or later. Update versions 4.0.0 through 4.4.6 to 4.4.7 or later.

Exploit

Fix

XSS

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56698
GHSA-C9CV-MQ2M-PPP3

Affected Products

Nuxt