Executive brief
Nuxt is a popular web framework for building Vue.js applications. A vulnerability in its standard link component allows attackers to inject malicious scripts or phishing content into links if the application displays user-provided URLs. If a user clicks such a link, an attacker could steal login sessions, perform actions on the user's behalf, or trick them into providing credentials on a fake page.
Technical details
A reflected DOM-based Cross-Site Scripting (XSS) vulnerability exists in the <NuxtLink> component due to insufficient validation of URL schemes in the 'to' and 'href' props. The component's external link auto-detection logic failed to reject script-capable protocols like 'javascript:', 'vbscript:', or 'data:'. An attacker can provide a malicious URL that, when rendered and clicked, executes arbitrary JavaScript in the context of the application's origin or facilitates same-tab phishing via 'data:text/html'. The issue is fixed in Nuxt 4.4.7 and 3.21.7 by sanitizing resolved external URLs and stripping script-capable schemes.
Affected products
- Nuxt Nuxt >= 4.0.0, < 4.4.7
- Nuxt Nuxt < 3.21.7
Timeline
- 2026-06-02: disclosed
- 2026-06-12: advisory: NVD publication
- 2026-06-16: patched: GitHub Advisory reviewed and updated