CVE-2026-56317
LOWNuxt - Cross-Site Scripting via NoScript Component Slot Content
Title source: cnaDescription
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-m3q2-p4fw-w38m
https://github.com/nuxt/nuxt/security/advisories/GHSA-m3q2-p4fw-w38m
Third Party Advisory third-party-advisory
VulnCheck Advisory: Nuxt - Cross-Site Scripting via NoScript Component Slot Content
https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-noscript-component-slot-content
Scores
CVSS v4
2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Details
CWE
CWE-79
Status
published
Products (4)
Nuxt/Nuxt
< 3.21.7
Nuxt/Nuxt
3.21.7
Nuxt/Nuxt
4.0.0 - 4.4.7
Nuxt/Nuxt
4.4.7
Published
Jun 20, 2026
Tracked Since
Jun 20, 2026