Threats Tagged 'cve-2026-53722'
View all threats tagged with 'cve-2026-53722'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-53722'
Click on any threat for detailed analysis and mitigation recommendations
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL (CVE-2026-53722)CVE-2026-53722 0 Nuxt versions prior to 4.4.7 and 3.21.7 contain a reflected DOM-based cross-site scripting (XSS) vulnerability in the <NuxtLink> component. This occurs because the component does not validate URL schemes in its 'to' or 'href' props, allowing attacker-controlled inputs with 'javascript:', 'vbscript:', or 'data:' URLs to be rendered directly into anchor href attributes. Clicking such links can execute malicious scripts in the application's origin or enable phishing attacks. The issue affects applications that bind user input to <NuxtLink> URLs, such as user profiles, CMS fields, or marketplace listings. The vulnerability is fixed in [email protected] and [email protected] by sanitizing and rejecting script-capable URL schemes before rendering. Join the discussion | GCVE Database | 06/16/2026, 13:49:36 UTC Added: 08/15/2026, 05:15:38 UTC |
Showing 1 to 1 of 1 result