Junglewise Threat Intelligence

CVE-2024-34343: Nuxt navigateTo cross-site scripting in server-side rendering

CVE-2024-34343 · Severity: low · CVSS 3.1 · Published 2024-08-05

Technologies: nuxt (npm). Vendors: Nuxt, npm.

Executive brief

Nuxt is a popular Vue.js-based web framework used to build interactive web applications. The navigateTo function, which redirects users to specified URLs after server-side rendering, improperly validates javascript: protocol URLs due to inconsistent URL parsing logic. An attacker can craft a malicious link that, when clicked on a rendered page, executes arbitrary JavaScript to steal cookies, session tokens, or perform actions on behalf of the user.

Technical details

The vulnerability exists in Nuxt's navigateTo function, which attempts to block dangerous javascript: protocol URLs but fails due to inconsistent URL parsing between the hasProtocol and parseURL functions from the unjs/ufo library. The function first checks if a URL has a protocol (which works), but then uses parseURL which refuses to parse malformed URLs like "javascript:alert(1)", returning empty values. The subsequent isScriptProtocol check cannot find a protocol in the malformed URL and allows it through. Additionally, whitespace characters (newlines, tabs) inserted into the URL bypass protocol validation. This vulnerability only affects client-side navigation after SSR has occurred; SSR-based redirects in location headers are not affected. The attack requires user interaction (clicking a malicious link). A fix was released in version 3.12.4.

Affected products

  • Nuxt Nuxt < 3.12.4

Timeline

  • 2024-08-05: disclosed
  • 2024-08-05: patched: Version 3.12.4 and later

References

Related threats