CVE Explorer
CVE-2026-31860
Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is the composable that Nuxt docs recommend for safely handling user-generated content. The acceptDataAttrs function (safe.ts, line 16-20) allows any property key starting with data- through to the final HTML. It only checks the prefix, not whether the key contains spaces or other characters that break HTM
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"unhead","vendor":"unjs","versions":[{"status":"affected","version":"< 2.1.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:529721d217710d4b3a359d168b169e93a3fbfb9badeb46be1b07e5ea57206c22 · sha256:5cc07e79e86069cc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:529721d217710d4b3a359d168b169e93a3fbfb9badeb46be1b07e5ea57206c22 · sha256:5cc07e79e86069cc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:529721d217710d4b3a359d168b169e93a3fbfb9badeb46be1b07e5ea57206c22 · sha256:5cc07e79e86069cc… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/unjs/unhead/security/advisories/GHSA-g5xx-pwrp-g3fv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/unjs/unhead/security/advisories/GHSA-g5xx-pwrp-g3fv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:529721d217710d4b3a359d168b169e93a3fbfb9badeb46be1b07e5ea57206c22 · sha256:5cc07e79e86069cc… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/unjs/unhead/security/advisories/GHSA-g5xx-pwrp-g3fv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:529721d217710d4b3a359d168b169e93a3fbfb9badeb46be1b07e5ea57206c22 · sha256:5cc07e79e86069cc… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.