CVE-2026-56317(nuxt / nuxt)

LOWCVSS 6.1 · MEDIUM

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nuxt

Affected systems

Vendors
Products
nuxt

Deep dive

Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56317 Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML wit… https://www.cve.org/CVERecord?id=CVE-2026-56317 ----- Traducción: CVE-2026-56317 Nux… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑56317, describing it as a cross‑site scripting flaw in Nuxt’s NoScript component and linking to the official CVE record, but provides no exploit, patch, or evidence of active use.

    0000045
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56317 Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML wit… https://www.cve.org/CVERecord?id=CVE-2026-56317

    Post summary

    The post announces CVE-2026-56317, a cross‑site scripting flaw in Nuxt’s NoScript component affecting versions before 4.4.7 and 3.21.7, without providing exploit code, patch information, or evidence of active attacks.

    00000394
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56317 Cross-Site Scripting in Nuxt NoScript Component Before 4.4.7 and 3.21.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56317

    Post summary

    The text announces CVE-2026-56317, a cross‑site scripting flaw in Nuxt NoScript component, without providing PoC, exploit, patch, or evidence of active exploitation.

    0000046
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnuxtnuxt---

Explore more