{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nuxtjs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nuxtjs:mdc:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-63671"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nuxtjs/mdc (\u003c 0.22.1)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","nuxtjs"],"_cs_type":"advisory","_cs_vendors":["NuxtJS"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@nuxtjs/mdc\u003c/code\u003e package is vulnerable to Cross-Site Scripting (XSS) due to insufficient sanitization of untrusted markdown input (CVE-2026-63671). The library parses markdown into a Vue component tree and uses a sanitizer to block dangerous HTML attributes and URI schemes. However, the sanitizer's attribute-checking logic only validates \u003ccode\u003ehref\u003c/code\u003e and \u003ccode\u003esrc\u003c/code\u003e, allowing the \u003ccode\u003exlink:href\u003c/code\u003e attribute on SVG elements to pass through unvalidated. Attackers can inject a \u003ccode\u003ejavascript:\u003c/code\u003e URI within an SVG \u003ccode\u003e\u0026lt;a\u0026gt;\u003c/code\u003e tag, which executes in the context of the page's origin when clicked.\u003c/p\u003e\n\u003cp\u003eAdditionally, the sanitizer's deny-list implementation for URI schemes fails to correctly handle \u003ccode\u003edata:\u003c/code\u003e URIs. It compares the \u003ccode\u003edata:\u003c/code\u003e protocol string against the list of forbidden prefixes, causing the check to consistently fail and permitting \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e elements to load \u003ccode\u003edata:text/html\u003c/code\u003e content. Since \u003ccode\u003eiframe\u003c/code\u003e is not included in the library's list of dangerous tags, this allows the execution of arbitrary script content within an opaque origin. These vulnerabilities exist by default, as the library enables dangerous HTML rendering without requiring custom configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to perform XSS attacks against users viewing markdown content rendered by \u003ccode\u003e@nuxtjs/mdc\u003c/code\u003e. This can lead to session hijacking, sensitive data theft, or arbitrary actions performed on behalf of the victim within the application context. The vulnerability affects all implementations of \u003ccode\u003e@nuxtjs/mdc\u003c/code\u003e version 0.22.1 and earlier that process user-supplied markdown.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@nuxtjs/mdc\u003c/code\u003e to version 0.22.1 or later immediately to patch the sanitization logic.\u003c/li\u003e\n\u003cli\u003eAudit applications currently using \u003ccode\u003e@nuxtjs/mdc\u003c/code\u003e to determine if they render untrusted user input, as this represents the primary threat vector for CVE-2026-63671.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, implement a secondary layer of sanitization or a strict Content Security Policy (CSP) that restricts \u003ccode\u003eframe-src\u003c/code\u003e and \u003ccode\u003escript-src\u003c/code\u003e to minimize the potential impact of injected scripts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T01:07:37Z","date_published":"2026-09-17T01:07:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nuxtjs-mdc-xss/","summary":"The @nuxtjs/mdc package contains an XSS vulnerability (CVE-2026-63671) due to improper sanitization of SVG xlink:href attributes and iframe data:text/html sources during markdown parsing.","title":"Cross-Site Scripting Vulnerability in @nuxtjs/mdc","url":"https://feed.craftedsignal.io/briefs/2026-09-nuxtjs-mdc-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - NuxtJS","version":"https://jsonfeed.org/version/1.1"}