VYPR
Medium severity5.4NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026

CVE-2026-53722

CVE-2026-53722

Description

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying element. When an application binds attacker-controlled input (a query parameter, a CMS field, a user-supplied profile URL) to or :href, the attacker can supply a javascript: or vbscript: URL that is reflected verbatim into the rendered markup. Clicking the link executes the supplied script in the origin of the Nuxt application, resulting in reflected DOM-based cross-site scripting. A data:text/html,... payload reflected through the same sink does not execute in the application's origin but enables a same-tab phishing surface anchored to a legitimate application link. The same value was exposed to consumers of the component's custom slot via the href and route.href props, so applications that re-bind those values to their own anchors were affected identically. This issue has been patched in versions 3.21.7 and 4.4.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nuxtnpm
>= 4.0.0, < 4.4.74.4.7
nuxtnpm
< 3.21.73.21.7

Affected products

3
  • Nuxt/Nuxtreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <3.21.7, <4.4.7
  • ghsa-coords
    Range: >= 4.0.0, < 4.4.7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.