https://advisories.gitlab.com/npm/unhead/CVE-2026-31860/
Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol...
CVE-2026-31860 Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check: useHeadSafe() can be bypassed to inject...
https://nuxt.com/docs/4.x/api/composables/use-head-safe
useHeadSafe ยท Nuxt Composables v4
The recommended way to provide head data with user input.
nuxtcomposables