Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect users to attacker-controlled hosts, enabling phishing and OAuth authorization-code theft.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect users to attacker-controlled hosts, enabling phishing and OAuth authorization-code theft. | |
| Title | Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp | |
| First Time appeared |
Nuxt
Nuxt og Image |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nuxt
Nuxt og Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T21:04:53.038Z
Reserved: 2026-06-22T17:09:16.556Z
Link: CVE-2026-56697
No data.
No data.
No data.
OpenCVE Enrichment
No data.