Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fx6j-w5w5-h468 | Nuxt: Reflected XSS in `navigateTo()` external redirect |
Mon, 15 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nuxt:nuxt:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt
Nuxt nuxt |
|
| Vendors & Products |
Nuxt
Nuxt nuxt |
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redirect body containing a <meta http-equiv="refresh"> tag. The destination URL is only sanitized by replacing " with %22, leaving <, >, &, and ' unencoded. An attacker who can influence the URL passed to navigateTo(url, { external: true }) can break out of the content="…" attribute and inject arbitrary HTML/JavaScript that executes under the application's origin. This issue has been patched in versions 3.21.6 and 4.4.6. | |
| Title | Nuxt: Reflected XSS in `navigateTo()` external redirect | |
| Weaknesses | CWE-83 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T14:07:21.725Z
Reserved: 2026-05-12T21:59:25.666Z
Link: CVE-2026-45669
Updated: 2026-06-12T14:03:45.577Z
Status : Analyzed
Published: 2026-06-12T14:16:31.297
Modified: 2026-06-15T18:09:37.427
Link: CVE-2026-45669
No data.
OpenCVE Enrichment
Updated: 2026-06-12T15:00:09Z
Github GHSA