{"id":"CVE-2026-56698","aliases":["CVE-2026-56326","CVE-2026-56697","GHSA-c9cv-mq2m-ppp3"],"url":"https://o3.security/vulnerability/CVE-2026-56698","summary":"Nuxt - Cross-Site Scripting via navigateTo open Option","details":"Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary scripts in the application's origin when user-controlled input is passed to navigateTo.","published":"2026-06-22T21:04:53.739Z","modified":"2026-08-12T03:51:40.215151002Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"nuxt","fixedVersion":"4.4.7"},{"ecosystem":"npm","name":"nuxt","fixedVersion":"3.21.7"}],"fix":{"url":"https://github.com/nuxt/nuxt/commit/3394716d4a913cba904b028df5338f2aead50032","label":"nuxt/nuxt@3394716"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56698.json"},{"type":"ADVISORY","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-c9cv-mq2m-ppp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56698"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-navigateto-open-option"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/commit/3394716d4a913cba904b028df5338f2aead50032"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/commit/62fc32eddf648b00a3890141e0235d2a222b024d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.215151002Z"}}