Skip to main content
EPSS 0.4%top 73%

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`…

0
Medium
Published: 06/16/2026 (06/16/2026, 13:47:52 UTC)
Source: GCVE Database
Product: nuxt

Description

Three URL-handling weaknesses in Nuxt's client-navigation APIs (`navigateTo` and `reloadNuxtApp`) allow SSR open redirects, client-side script execution, and protocol-relative bypasses. These vulnerabilities can lead to phishing, OAuth token theft, or reflected XSS if user-controlled input is passed unsafely. Fixed in nuxt versions 4.4.7 and 3.21.7.

CVSS v3.1

Score 6.1medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected software

npmghsa
nuxt
Affected versions
>=3.5.0 <3.21.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/19/2026, 02:11:36 UTC

Technical Analysis

This advisory details three related vulnerabilities in Nuxt's navigation functions. CVE-2026-56326 is an SSR open redirect caused by path-normalisation bypass in `navigateTo`, where certain crafted paths starting with '/' normalize to protocol-relative URLs, enabling cross-origin redirects. CVE-2026-56698 allows client-side script execution via `navigateTo({ open: ... })` because the early-open handler does not check for script protocols, enabling reflected XSS with javascript: URLs. CVE-2026-56697 is an open redirect in `reloadNuxtApp` via protocol-relative URL bypass, where URLs like `//evil.com` resolve to the current protocol and bypass script protocol checks, causing cross-origin redirects. These issues affect Nuxt versions >=3.5.0 <3.21.7 and >=4.0.0 <4.4.7 and have been fixed in 3.21.7 and 4.4.7 respectively.

Potential Impact

The SSR open redirect (CVE-2026-56326) can be exploited for phishing or OAuth code theft in Nuxt apps that pass user-controlled input to `navigateTo` on the server, undermining the framework's external host blocking. The client-side script execution (CVE-2026-56698) enables reflected XSS in the application's origin if untrusted URLs are passed to `navigateTo` with the `open` option. The open redirect in `reloadNuxtApp` (CVE-2026-56697) allows cross-origin redirects even in versions with script protocol guards, risking phishing and token theft. No known exploits in the wild have been reported.

Mitigation Recommendations

A fix is available in [email protected] and [email protected] that addresses all three vulnerabilities. Users should upgrade to these versions or later. As a workaround, validate and sanitize redirect targets before passing them to `navigateTo` or `reloadNuxtApp`: reject paths starting with `//` or those that resolve to external hosts. For `navigateTo({ open })`, restrict allowed protocols to safe schemes like http and https. These mitigations reduce risk until patched versions are deployed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-c9cv-mq2m-ppp3
Osv Schema Version
1.4.0
Aliases
["CVE-2026-56326"]
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a7ff5fabf8831d5398804f2

Added to database: 08/15/2026, 05:15:38 UTC

Last enriched: 09/19/2026, 02:11:36 UTC

Last updated: 09/30/2026, 06:54:39 UTC

Views: 70

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses