CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-53722

PENDING
N/A
CVSS Severity Score
EPSS Score0.0740%
EPSS Percentile9.39th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. When an application binds attacker-controlled input (a query parameter, a CMS field, a user-supplied profile URL) to <NuxtLink :to> or :href, the attacker can supply a javascript: or vbscript: URL that is reflected verbatim into the rendered markup. Clicking the link executes the supplied script in the origin of the Nuxt application, resulting in reflected DOM-based cross-site scripting. A data:text/html,... payload reflected through the same sink does not execute in the application's origin but enables a same-tab phishing surface anchored to a legitimate application link. The same value was exposed to consumers of the component's custom slot via the href and route.href props, so applications that re-bind those values to their own anchors were affected identically. This issue has been patched in versions 3.21.7 and 4.4.7.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報