CVE-2026-56317

low

Description

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.

References

https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-noscript-component-slot-content

https://github.com/nuxt/nuxt/security/advisories/GHSA-m3q2-p4fw-w38m

https://github.com/nuxt/nuxt/commit/7fea9fd687f1dacbfb63db5fae5839896b017a0e

https://github.com/nuxt/nuxt/commit/4b054e9d95f8daf366cb144b52782047c511a66e

Details

Source: Mitre, NVD

Published: 2026-06-20

Updated: 2026-06-20

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 2.3

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Low