CVE-2026-56317: Nuxt - Cross-Site Scripting via NoScript Component Slot Content
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56317?
The severity of CVE-2026-56317 is rated at 52, indicating a significant risk associated with the vulnerability.
How do I fix CVE-2026-56317?
To fix CVE-2026-56317, upgrade Nuxt to version 4.4.7 or higher, or to 3.21.7 or higher for the 3.x branch.
What type of vulnerability is CVE-2026-56317?
CVE-2026-56317 is a Cross-Site Scripting (XSS) vulnerability found in the Nuxt framework.
Where can I find more details about CVE-2026-56317?
More details about CVE-2026-56317 can be found in the GitHub security advisories for Nuxt.
Who is affected by CVE-2026-56317?
Anyone using Nuxt versions before 4.4.7 or the 3.x branch before 3.21.7 is affected by CVE-2026-56317.