Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect users to attacker-controlled hosts, enabling phishing and OAuth authorization-code theft.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt nuxt
|
|
| Vendors & Products |
Nuxt nuxt
|
Mon, 22 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect users to attacker-controlled hosts, enabling phishing and OAuth authorization-code theft. | |
| Title | Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp | |
| First Time appeared |
Nuxt
Nuxt og Image |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nuxt
Nuxt og Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-22T21:04:53.038Z
Updated: 2026-06-23T13:51:01.421Z
Reserved: 2026-06-22T17:09:16.556Z
Link: CVE-2026-56697
Updated: 2026-06-23T13:50:41.888Z
No data.
No data.
ReportizFlow