Vulnerabilities

Last updated 2 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
nuxt Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp` Medium Risk 6.1 3 months ago 5 hours ago
nuxt Nuxt dev server vite-node IPC socket is world-connectable on Linux Medium Risk 5.5 3 months ago 9 days ago
nuxt-og-image Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter Medium Risk 6.0 15 days ago 15 days ago
@nuxtjs/mdc @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration High Risk 8.1 16 days ago 16 days ago
@clerk/nuxt Clerk has an authorization bypass when combining organization, billing, or reverification checks High Risk 8.1 5 months ago 23 days ago
@nuxtjs/mdc Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering High Risk 8.3 1 year ago 23 days ago
@nuxt/rspack-builder @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) Medium Risk 6.0 3 months ago 23 days ago
@nuxt/webpack-builder @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) Medium Risk 6.0 3 months ago 23 days ago
nuxt-api-party DOS by abusing `fetchOptions.retry`. High Risk 7.5 2 years ago 23 days ago
nuxt-api-party SSRF & Credentials Leak High Risk 7.5 2 years ago 23 days ago
nuxt-ollama Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High Risk 7.5 23 days ago 23 days ago
nuxt Cross-site scripting via <NoScript> slot content in Nuxt's head components Low Risk 3.0 3 months ago 23 days ago
@nuxt/devtools Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical 9.6 1 month ago 1 month ago
nuxt Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Medium Risk 6.0 3 months ago 1 month ago
nuxt Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Medium Risk 6.0 1 month ago 1 month ago
@depup/nuxt Malicious code in @depup/nuxt (npm) Unknown 1 month ago 1 month ago
@sentry/nuxt Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` Medium Risk 6.0 10 months ago 1 month ago
nuxt Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props High Risk 8.1 1 month ago 1 month ago
nuxt Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation High Risk 7.5 1 month ago 1 month ago
nuxt Nuxt: Unauthorized Component Instantiation via Server Island Props Medium Risk 4.8 1 month ago 1 month ago
nuxt Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients High Risk 7.5 1 month ago 1 month ago
nuxt Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering High Risk 7.5 1 month ago 1 month ago
nuxt Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) High Risk 8.2 1 month ago 1 month ago
@nuxt/ui @nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration Medium Risk 6.0 3 months ago 1 month ago
nuxt Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Medium Risk 5.4 4 months ago 2 months ago
@nuxt/nitro-server Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Medium Risk 5.4 4 months ago 2 months ago
nuxt Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` Medium Risk 5.3 4 months ago 2 months ago
@nuxt/nitro-server Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` Medium Risk 5.3 4 months ago 2 months ago
@nuxt/rspack-builder Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) Medium Risk 5.4 4 months ago 2 months ago
@nuxt/webpack-builder Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) Medium Risk 5.4 4 months ago 2 months ago
nuxt Nuxt: Reflected XSS in `navigateTo()` external redirect Medium Risk 5.4 4 months ago 2 months ago
load-nuxt Malicious code in load-nuxt (npm) Unknown 2 months ago 2 months ago
load-nuxt-dev Malicious code in load-nuxt-dev (npm) Unknown 2 months ago 2 months ago
nuxt-fonts-devtools Malicious code in nuxt-fonts-devtools (npm) Unknown 2 months ago 2 months ago
@nuxt/rspack-builder Opening a malicious website while running a Nuxt dev server could allow read-only access to code Medium Risk 5.3 1 year ago 2 months ago
@nuxt/webpack-builder Opening a malicious website while running a Nuxt dev server could allow read-only access to code Medium Risk 5.3 1 year ago 2 months ago
nuxt Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher High Risk 8.0 3 months ago 3 months ago
nuxt Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json` Low Risk 3.0 3 months ago 3 months ago
@shwfed/nuxt Malicious code in @shwfed/nuxt (npm) Unknown 4 months ago 3 months ago
nuxt-og-image nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect) Low Risk 3.7 4 months ago 4 months ago
@clerk/nuxt Official Clerk JavaScript SDKs: Middleware-based route protection bypass Critical 9.1 5 months ago 5 months ago
@hrb-web/nuxt Malicious code in @hrb-web/nuxt (npm) Unknown 5 months ago 5 months ago
nuxt-og-image Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes Medium Risk 6.1 6 months ago 5 months ago
nuxt-og-image Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions Medium Risk 6.0 6 months ago 5 months ago
nuxt-og-image Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters Medium Risk 5.3 6 months ago 6 months ago
@opposhop/nuxt-ssr-cache Malicious code in @opposhop/nuxt-ssr-cache (npm) Unknown 7 months ago 7 months ago
@nuxt/vite-builder Opening a malicious website while running a Nuxt dev server could allow read-only access to code Medium Risk 5.3 1 year ago 8 months ago
vue-browserupdate-nuxt Malicious code in vue-browserupdate-nuxt (npm) Unknown 10 months ago 10 months ago
nuxt-keycloak Malicious code in nuxt-keycloak (npm) Unknown 10 months ago 10 months ago
@pergel/nuxt Malicious code in @pergel/nuxt (npm) Unknown 10 months ago 10 months ago