Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`…
Three URL-handling weaknesses in Nuxt's client-navigation APIs (`navigateTo` and `reloadNuxtApp`) allow SSR open redirects, client-side script execution, and protocol-relative bypasses. These vulnerabilities can lead to phishing, OAuth token theft, or reflected XSS if user-controlled input is passed unsafely. Fixed in nuxt versions 4.4.7 and 3.21.7.
AI Analysis
Technical Summary
This advisory details three related vulnerabilities in Nuxt's navigation functions. CVE-2026-56326 is an SSR open redirect caused by path-normalisation bypass in `navigateTo`, where certain crafted paths starting with '/' normalize to protocol-relative URLs, enabling cross-origin redirects. CVE-2026-56698 allows client-side script execution via `navigateTo({ open: ... })` because the early-open handler does not check for script protocols, enabling reflected XSS with javascript: URLs. CVE-2026-56697 is an open redirect in `reloadNuxtApp` via protocol-relative URL bypass, where URLs like `//evil.com` resolve to the current protocol and bypass script protocol checks, causing cross-origin redirects. These issues affect Nuxt versions >=3.5.0 <3.21.7 and >=4.0.0 <4.4.7 and have been fixed in 3.21.7 and 4.4.7 respectively.
Potential Impact
The SSR open redirect (CVE-2026-56326) can be exploited for phishing or OAuth code theft in Nuxt apps that pass user-controlled input to `navigateTo` on the server, undermining the framework's external host blocking. The client-side script execution (CVE-2026-56698) enables reflected XSS in the application's origin if untrusted URLs are passed to `navigateTo` with the `open` option. The open redirect in `reloadNuxtApp` (CVE-2026-56697) allows cross-origin redirects even in versions with script protocol guards, risking phishing and token theft. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in [email protected] and [email protected] that addresses all three vulnerabilities. Users should upgrade to these versions or later. As a workaround, validate and sanitize redirect targets before passing them to `navigateTo` or `reloadNuxtApp`: reject paths starting with `//` or those that resolve to external hosts. For `navigateTo({ open })`, restrict allowed protocols to safe schemes like http and https. These mitigations reduce risk until patched versions are deployed.
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`…
Description
Three URL-handling weaknesses in Nuxt's client-navigation APIs (`navigateTo` and `reloadNuxtApp`) allow SSR open redirects, client-side script execution, and protocol-relative bypasses. These vulnerabilities can lead to phishing, OAuth token theft, or reflected XSS if user-controlled input is passed unsafely. Fixed in nuxt versions 4.4.7 and 3.21.7.
CVSS v3.1
Score 6.1medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory details three related vulnerabilities in Nuxt's navigation functions. CVE-2026-56326 is an SSR open redirect caused by path-normalisation bypass in `navigateTo`, where certain crafted paths starting with '/' normalize to protocol-relative URLs, enabling cross-origin redirects. CVE-2026-56698 allows client-side script execution via `navigateTo({ open: ... })` because the early-open handler does not check for script protocols, enabling reflected XSS with javascript: URLs. CVE-2026-56697 is an open redirect in `reloadNuxtApp` via protocol-relative URL bypass, where URLs like `//evil.com` resolve to the current protocol and bypass script protocol checks, causing cross-origin redirects. These issues affect Nuxt versions >=3.5.0 <3.21.7 and >=4.0.0 <4.4.7 and have been fixed in 3.21.7 and 4.4.7 respectively.
Potential Impact
The SSR open redirect (CVE-2026-56326) can be exploited for phishing or OAuth code theft in Nuxt apps that pass user-controlled input to `navigateTo` on the server, undermining the framework's external host blocking. The client-side script execution (CVE-2026-56698) enables reflected XSS in the application's origin if untrusted URLs are passed to `navigateTo` with the `open` option. The open redirect in `reloadNuxtApp` (CVE-2026-56697) allows cross-origin redirects even in versions with script protocol guards, risking phishing and token theft. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in [email protected] and [email protected] that addresses all three vulnerabilities. Users should upgrade to these versions or later. As a workaround, validate and sanitize redirect targets before passing them to `navigateTo` or `reloadNuxtApp`: reject paths starting with `//` or those that resolve to external hosts. For `navigateTo({ open })`, restrict allowed protocols to safe schemes like http and https. These mitigations reduce risk until patched versions are deployed.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c9cv-mq2m-ppp3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56326"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7ff5fabf8831d5398804f2
Added to database: 08/15/2026, 05:15:38 UTC
Last enriched: 09/19/2026, 02:11:36 UTC
Last updated: 09/30/2026, 06:54:39 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.