CVE-2026-56317
MEDIUMNuxt - Cross-Site Scripting via NoScript Component Slot Content
Title source: cnaDescription
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-m3q2-p4fw-w38m
https://github.com/nuxt/nuxt/security/advisories/GHSA-m3q2-p4fw-w38m
Third Party Advisory third-party-advisory
VulnCheck Advisory: Nuxt - Cross-Site Scripting via NoScript Component Slot Content
https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-noscript-component-slot-content
Scores
CVSS v3
6.1
EPSS
0.0021
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (5)
Nuxt/Nuxt
< 3.21.7
nuxt/nuxt
< 3.21.7
Nuxt/Nuxt
3.21.7
Nuxt/Nuxt
4.0.0 - 4.4.7
Nuxt/Nuxt
4.4.7
Published
Jun 20, 2026
Tracked Since
Jun 20, 2026