CVE-2026-53722
Description
Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying element. When an application binds attacker-controlled input (a query parameter, a CMS field, a user-supplied profile URL) to or :href, the attacker can supply a javascript: or vbscript: URL that is reflected verbatim into the rendered markup. Clicking the link executes the supplied script in the origin of the Nuxt application, resulting in reflected DOM-based cross-site scripting. A data:text/html,... payload reflected through the same sink does not execute in the application's origin but enables a same-tab phishing surface anchored to a legitimate application link. The same value was exposed to consumers of the component's custom slot via the href and route.href props, so applications that re-bind those values to their own anchors were affected identically. This issue has been patched in versions 3.21.7 and 4.4.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nuxtnpm | >= 4.0.0, < 4.4.7 | 4.4.7 |
nuxtnpm | < 3.21.7 | 3.21.7 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/nuxt/nuxt/commit/0103ce06fbbbdfa079a7f020ef8ce00121eac4a3nvdPatchWEB
- github.com/nuxt/nuxt/commit/53284043dc21210a25d629d1cec67d3ae557ffd0nvdPatchWEB
- github.com/nuxt/nuxt/security/advisories/GHSA-934w-87qh-qr26nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-934w-87qh-qr26ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53722ghsaADVISORY
News mentions
0No linked articles in our index yet.