A vulnerability classified as problematic has been found in Nuxt up to 3.21.5/4.4.5. Affected by this vulnerability is an unknown functionality of the file /__nuxt_island/. This manipulation causes cross site scripting.

The identification of this vulnerability is CVE-2026-46342. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.