Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp` | Medium Risk 6.1 | 3 months ago | 5 hours ago |
|
|
Nuxt dev server vite-node IPC socket is world-connectable on Linux | Medium Risk 5.5 | 3 months ago | 9 days ago |
|
|
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter | Medium Risk 6.0 | 15 days ago | 15 days ago |
|
|
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration | High Risk 8.1 | 16 days ago | 16 days ago |
|
|
Clerk has an authorization bypass when combining organization, billing, or reverification checks | High Risk 8.1 | 5 months ago | 23 days ago |
|
|
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering | High Risk 8.3 | 1 year ago | 23 days ago |
|
|
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) | Medium Risk 6.0 | 3 months ago | 23 days ago |
|
|
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) | Medium Risk 6.0 | 3 months ago | 23 days ago |
|
|
DOS by abusing `fetchOptions.retry`. | High Risk 7.5 | 2 years ago | 23 days ago |
|
|
SSRF & Credentials Leak | High Risk 7.5 | 2 years ago | 23 days ago |
|
|
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients | High Risk 7.5 | 23 days ago | 23 days ago |
|
|
Cross-site scripting via <NoScript> slot content in Nuxt's head components | Low Risk 3.0 | 3 months ago | 23 days ago |
|
|
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host | Critical 9.6 | 1 month ago | 1 month ago |
|
|
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL | Medium Risk 6.0 | 3 months ago | 1 month ago |
|
|
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint | Medium Risk 6.0 | 1 month ago | 1 month ago |
|
|
Malicious code in @depup/nuxt (npm) | Unknown | 1 month ago | 1 month ago |
|
|
Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` | Medium Risk 6.0 | 10 months ago | 1 month ago |
|
|
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | High Risk 8.1 | 1 month ago | 1 month ago |
|
|
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
Nuxt: Unauthorized Component Instantiation via Server Island Props | Medium Risk 4.8 | 1 month ago | 1 month ago |
|
|
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) | High Risk 8.2 | 1 month ago | 1 month ago |
|
|
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration | Medium Risk 6.0 | 3 months ago | 1 month ago |
|
|
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` | Medium Risk 5.3 | 4 months ago | 2 months ago |
|
|
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` | Medium Risk 5.3 | 4 months ago | 2 months ago |
|
|
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Nuxt: Reflected XSS in `navigateTo()` external redirect | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Malicious code in load-nuxt (npm) | Unknown | 2 months ago | 2 months ago |
|
|
Malicious code in load-nuxt-dev (npm) | Unknown | 2 months ago | 2 months ago |
|
|
Malicious code in nuxt-fonts-devtools (npm) | Unknown | 2 months ago | 2 months ago |
|
|
Opening a malicious website while running a Nuxt dev server could allow read-only access to code | Medium Risk 5.3 | 1 year ago | 2 months ago |
|
|
Opening a malicious website while running a Nuxt dev server could allow read-only access to code | Medium Risk 5.3 | 1 year ago | 2 months ago |
|
|
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher | High Risk 8.0 | 3 months ago | 3 months ago |
|
|
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json` | Low Risk 3.0 | 3 months ago | 3 months ago |
|
|
Malicious code in @shwfed/nuxt (npm) | Unknown | 4 months ago | 3 months ago |
|
|
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect) | Low Risk 3.7 | 4 months ago | 4 months ago |
|
|
Official Clerk JavaScript SDKs: Middleware-based route protection bypass | Critical 9.1 | 5 months ago | 5 months ago |
|
|
Malicious code in @hrb-web/nuxt (npm) | Unknown | 5 months ago | 5 months ago |
|
|
Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes | Medium Risk 6.1 | 6 months ago | 5 months ago |
|
|
Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters | Medium Risk 5.3 | 6 months ago | 6 months ago |
|
|
Malicious code in @opposhop/nuxt-ssr-cache (npm) | Unknown | 7 months ago | 7 months ago |
|
|
Opening a malicious website while running a Nuxt dev server could allow read-only access to code | Medium Risk 5.3 | 1 year ago | 8 months ago |
|
|
Malicious code in vue-browserupdate-nuxt (npm) | Unknown | 10 months ago | 10 months ago |
|
|
Malicious code in nuxt-keycloak (npm) | Unknown | 10 months ago | 10 months ago |
|
|
Malicious code in @pergel/nuxt (npm) | Unknown | 10 months ago | 10 months ago |
Page 1