CVE-2026-56326
EUVD-2026-3837522.06.2026, 22:16
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host checks using path-normalization techniques to redirect users to attacker-controlled sites via the Location header or meta-refresh, enabling phishing and OAuth authorization-code theft.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nuxt | nuxt | 3.0.0 ≤ 𝑥 < 3.21.7 |
| nuxt | nuxt | 4.0.0 ≤ 𝑥 < 4.4.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References