Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary scripts in the application's origin when user-controlled input is passed to navigateTo.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 22 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary scripts in the application's origin when user-controlled input is passed to navigateTo. | |
| Title | Nuxt - Cross-Site Scripting via navigateTo open Option | |
| First Time appeared |
Nuxt
Nuxt og Image |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nuxt
Nuxt og Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T21:04:53.739Z
Reserved: 2026-06-22T17:09:16.556Z
Link: CVE-2026-56698
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses