PatchSiren cyber security CVE debrief
CVE-2026-53722 nuxt CVE debrief
CVE-2026-53722 is a reflected DOM-based cross-site scripting vulnerability in the Nuxt open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, the <NuxtLink> component did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. This allows an attacker to supply a javascript: or vbscript: URL that is reflected verbatim into the rendered markup. Clicking the link executes the supplied script in the origin of the Nuxt application, resulting in reflected DOM-based cross-site scripting. The vulnerability has been patched in versions 3.21.7 and 4.4.7.
- Vendor
- nuxt
- Product
- Unknown
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-15
Who should care
Developers and users of the Nuxt open-source web development framework for Vue.js, especially those who bind attacker-controlled input to <NuxtLink :to> or :href.
Technical summary
The <NuxtLink> component in Nuxt did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. This allows an attacker to supply a malicious URL that is reflected verbatim into the rendered markup, leading to reflected DOM-based cross-site scripting.
Defensive priority
MEDIUM
Recommended defensive actions
- Update to Nuxt versions 3.21.7 or 4.4.7 or later.
- Validate and sanitize user-supplied input bound to <NuxtLink :to> or :href.
- Use a Content Security Policy (CSP) to restrict the types of scripts that can be executed on your application.
Evidence notes
CVE-2026-53722 has a CVSS score of 5.1 and is classified as MEDIUM severity. The vulnerability was published on 2026-06-12T15:16:31.427Z and modified on 2026-06-12T16:01:25.477Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nuxt/nuxt/commit/0103ce06fbbbdfa079a7f020ef8ce00121eac4a3
-
Source reference
Unverified legacy reference
URL: https://github.com/nuxt/nuxt/commit/53284043dc21210a25d629d1cec67d3ae557ffd0
-
Source reference
Unverified legacy reference
URL: https://github.com/nuxt/nuxt/security/advisories/GHSA-934w-87qh-qr26
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.