CVE-2026-53722 PUBLISHED

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Assigner: GitHub_M
Reserved: 10.06.2026 Published: 12.06.2026 Updated: 12.06.2026

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor nuxt
Product nuxt
Versions
  • Version < 3.21.7 is affected
  • Version >= 4.0.0, < 4.4.7 is affected

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE
  • CWE-83: Improper Neutralization of Script in Attributes in a Web Page CWE