Cross-site scripting in Vuejs - #VU146304
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary web script in server-rendered HTML.
The vulnerability exists due to cross-site scripting in ssrRenderAttrs() and isSSRSafeAttrName() in @vue/server-renderer when rendering dynamic attribute names from an attacker-controlled object via v-bind. A remote attacker can supply a crafted attribute key containing a carriage return character to inject arbitrary web script in server-rendered HTML.
The issue is specific to server-side rendering and can be triggered without user interaction when the injected attributes include self-triggering event handler combinations such as autofocus with onfocus.