{"id":"CVE-2026-56326","aliases":["CVE-2026-56697","CVE-2026-56698","GHSA-c9cv-mq2m-ppp3"],"url":"https://o3.security/vulnerability/CVE-2026-56326","summary":"Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo","details":"Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host checks using path-normalization techniques to redirect users to attacker-controlled sites via the Location header or meta-refresh, enabling phishing and OAuth authorization-code theft.","published":"2026-06-22T21:04:50.975Z","modified":"2026-08-12T03:51:08.390525059Z","cvss":null,"epss":{"score":0.00362,"percentile":0.29098,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"nuxt","fixedVersion":"4.4.7"},{"ecosystem":"npm","name":"nuxt","fixedVersion":"3.21.7"}],"fix":{"url":"https://github.com/nuxt/nuxt/commit/1f2dd5e78c77576437138e97671965573c232835","label":"nuxt/nuxt@1f2dd5e"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56326.json"},{"type":"ADVISORY","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-c9cv-mq2m-ppp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56326"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nuxt-server-side-open-redirect-via-path-normalization-bypass-in-navigateto"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/commit/1f2dd5e78c77576437138e97671965573c232835"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/commit/2cce6fb02e621196d56df92e05594e07469b5a6d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:08.390525059Z"}}