Nuxt disclosed CVE-2026-53722, a reflected DOM-based cross-site scripting flaw in the <NuxtLink> component affecting versions before 3.21.7 and 4.4.7. The bug allowed attacker-controlled values passed into to or href to be rendered into anchor tags without proper URI scheme sanitization, enabling javascript: or data: payloads to execute when a victim clicked the link. The issue is exploitable in applications that feed untrusted query parameters or database values into <NuxtLink>, and Nuxt fixed it by introducing sanitizeExternalHref to block unsafe protocols and abort navigation.
Angular also disclosed an SSRF vulnerability in @angular/platform-server under GHSA-rfh7-fxqc-q52v, caused by server-side rendering logic that accepted absolute-form request URLs and could adopt an attacker-controlled hostname. That behavior could redirect relative HttpClient requests or PlatformLocation.hostname lookups to attacker infrastructure, potentially exposing internal APIs or cloud metadata services during rendering. Patched releases include 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22; no fix was listed for the 18.x line. Organizations using either framework were advised to upgrade promptly and, where patching is delayed, enforce URL scheme allowlisting in Nuxt and validate or normalize SSR request URLs in Angular.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Angular addressed CVE-2026-50168, a high-severity SSRF flaw in @angular/platform-server caused by a parser differential between Node's WHATWG URL parser and Domino's lenient parser. The issue lets attackers bypass host allowlist checks with malformed URLs and was fixed in versions 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.
A reflected DOM-based cross-site scripting vulnerability affecting Nuxt's <NuxtLink> component was reported as CVE-2026-53722. The issue affects versions prior to 3.21.7 and 4.4.7 and was addressed by adding sanitizeExternalHref to block unsafe URI schemes.
Angular published advisory GHSA-rfh7-fxqc-q52v for a server-side request forgery vulnerability in @angular/platform-server caused by hostname hijacking during server-side rendering. The advisory lists patched versions 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, and notes no patch for the 18.x line.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.