Vulnerabilities/

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

Severity:
Medium

Description

The navigateTo function attempts to blockthe javascript: protocol, but does not correctly use API’s provided by unjs/ufo. This library also contains parsing discrepancies.

Recommendation

Update the nuxt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nuxt
Anything's wrong? Let us know Last updated on May 15, 2025

This issue is available in SmartScanner Professional

See Pricing