Junglewise Threat Intelligence

CVE-2026-53722: Nuxt NuxtLink reflected cross-site scripting via unsanitized URL schemes

CVE-2026-53722 · Severity: medium · CVSS 4 · Published 2026-06-12

Vendors: Nuxt.

Executive brief

Nuxt is a popular web framework for building Vue.js applications. A vulnerability in its standard link component allows attackers to inject malicious scripts or phishing content into links if the application displays user-provided URLs. If a user clicks such a link, an attacker could steal login sessions, perform actions on the user's behalf, or trick them into providing credentials on a fake page.

Technical details

A reflected DOM-based Cross-Site Scripting (XSS) vulnerability exists in the <NuxtLink> component due to insufficient validation of URL schemes in the 'to' and 'href' props. The component's external link auto-detection logic failed to reject script-capable protocols like 'javascript:', 'vbscript:', or 'data:'. An attacker can provide a malicious URL that, when rendered and clicked, executes arbitrary JavaScript in the context of the application's origin or facilitates same-tab phishing via 'data:text/html'. The issue is fixed in Nuxt 4.4.7 and 3.21.7 by sanitizing resolved external URLs and stripping script-capable schemes.

Affected products

  • Nuxt Nuxt >= 4.0.0, < 4.4.7
  • Nuxt Nuxt < 3.21.7

Timeline

  • 2026-06-02: disclosed
  • 2026-06-12: advisory: NVD publication
  • 2026-06-16: patched: GitHub Advisory reviewed and updated

References