Executive brief
Nuxt, a popular web development framework, contains vulnerabilities in how it handles website navigation and page reloads. An attacker could use these flaws to trick users into visiting malicious websites (phishing) or to execute unauthorized scripts in the user's browser (XSS). This could lead to the theft of sensitive information like login tokens or personal data.
Technical details
Nuxt is vulnerable to three distinct URL-handling flaws. First, navigateTo is susceptible to an SSR open redirect via path-normalization bypass (e.g., using /..//evil.com) because it fails to correctly identify external hosts before writing to the Location header. Second, navigateTo with the 'open' option fails to check for script-capable protocols, allowing reflected XSS via 'javascript:' URIs. Third, reloadNuxtApp is vulnerable to an open redirect via protocol-relative paths (e.g., //evil.com) which bypass existing protocol guards. These issues are reachable via public APIs when user-controlled input is passed without sufficient validation. Patches are available in Nuxt versions 4.4.7 and 3.21.7.
Affected products
- Nuxt Nuxt >= 4.0.0, < 4.4.7
- Nuxt Nuxt < 3.21.7
Timeline
- 2026-06-02: disclosed: Initial publication date
- 2026-06-16: advisory: GitHub Advisory published/updated