{"id":"CVE-2026-45669","aliases":["GHSA-fx6j-w5w5-h468"],"url":"https://o3.security/vulnerability/CVE-2026-45669","summary":"Nuxt: Reflected XSS in `navigateTo()` external redirect","details":"Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redirect body containing a <meta http-equiv=\"refresh\"> tag. The destination URL is only sanitized by replacing \" with %22, leaving <, >, &, and ' unencoded. An attacker who can influence the URL passed to navigateTo(url, { external: true }) can break out of the content=\"…\" attribute and inject arbitrary HTML/JavaScript that executes under the application's origin. This issue has been patched in versions 3.21.6 and 4.4.6.","published":"2026-06-12T12:51:42.640Z","modified":"2026-08-12T03:51:13.619414387Z","cvss":null,"epss":{"score":0.00177,"percentile":0.0744,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"nuxt","fixedVersion":"3.21.6"},{"ecosystem":"npm","name":"nuxt","fixedVersion":"4.4.6"}],"fix":{"url":"https://github.com/nuxt/nuxt/pull/35052","label":"nuxt/nuxt#35052"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45669.json"},{"type":"ADVISORY","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-fx6j-w5w5-h468"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45669"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/pull/35052"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.619414387Z"}}