{"id":"GHSA-m3q2-p4fw-w38m","summary":"Cross-site scripting via \u003cNoScript\u003e slot content in Nuxt's head components","details":"### Impact\n\nNuxt's globally registered `\u003cNoScript\u003e` component (from `@unhead/vue` head components, re-exported by Nuxt) wrote its default-slot content to the `innerHTML` of the `\u003cnoscript\u003e` head tag, bypassing the HTML escaping that `{{ }}` interpolation normally applies in Vue templates.\n\nApplications that placed untrusted, attacker-controllable data inside a `\u003cNoScript\u003e` slot, for example:\n\n```vue\n\u003cNoScript\u003e{{ route.query.banner }}\u003c/NoScript\u003e\n```\n\nwould emit that value unescaped inside `\u003cnoscript\u003e` in the server-rendered HTML. With scripting enabled, the HTML parser treats `\u003cnoscript\u003e` content in `\u003chead\u003e` under the \"in head noscript\" insertion mode: any tag other than `link`, `meta`, `noframes`, or `style` implicitly closes `\u003cnoscript\u003e` and is re-processed in the head. A payload such as `\u003cscript\u003e...\u003c/script\u003e` therefore escapes the element and executes in the document context.\n\nSibling head components (`\u003cStyle\u003e`, `\u003cTitle\u003e`) were not affected because they already routed slot text through the safe `textContent` path.\n\n### Affected versions\n\nAll currently supported versions of `nuxt` that ship the `\u003cNoScript\u003e` global component.\n\n### Patches\n\nFixed in `nuxt@4.4.7` (commit [`4b054e9d`](https://github.com/nuxt/nuxt/commit/4b054e9d95f8daf366cb144b52782047c511a66e)) and backported to `nuxt@3.21.7` (commit [`7fea9fd6`](https://github.com/nuxt/nuxt/commit/7fea9fd687f1dacbfb63db5fae5839896b017a0e)). The fix escapes `\u003cNoScript\u003e` slot content with `escapeHtml` from `@vue/shared` and writes it to `textContent` rather than `innerHTML`. Slot content is now rendered as text; intentional markup inside `\u003cNoScript\u003e` is no longer parsed as HTML.\n\n### Workarounds\n\nUntil you can upgrade:\n\n- Do not interpolate untrusted input into `\u003cNoScript\u003e` slots. Replace `\u003cNoScript\u003e{{ x }}\u003c/NoScript\u003e` with a static string, or sanitise / HTML-escape `x` at the source.\n- If you must render dynamic noscript content, write the tag yourself via `useHead({ noscript: [{ textContent: escapedValue }] })` after escaping `escapedValue`.\n\n### Credit\n\nReported to Anthropic's coordinated vulnerability disclosure pipeline by Claude (Anthropic's AI assistant) and triaged by the Anthropic security team. Reference: ANT-2026-4NJYDFFM.\n\nIndependently reported by [@alcls01111](https://github.com/alcls01111) via GitHub's coordinated disclosure flow (`GHSA-8grp-wcq9-925q`), closed as a duplicate of this advisory.","aliases":["CVE-2026-56317"],"modified":"2026-09-10T00:00:05.363724613Z","published":"2026-06-16T23:38:47Z","database_specific":{"github_reviewed_at":"2026-06-16T23:38:47Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-m3q2-p4fw-w38m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56317"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/4b054e9d95f8daf366cb144b52782047c511a66e"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/7fea9fd687f1dacbfb63db5fae5839896b017a0e"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/nuxt-cross-site-scripting-via-noscript-component-slot-content"}],"affected":[{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.4.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-m3q2-p4fw-w38m/GHSA-m3q2-p4fw-w38m.json"}},{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.21.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-m3q2-p4fw-w38m/GHSA-m3q2-p4fw-w38m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}