Nuxt
This hub aggregates every CVE we track for Nuxt, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
3
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM16HIGH11CRITICAL3LOW1
Monthly trend
0
0
0
0
2
0
1
0
0
0
0
0
1
0
0
0
0
0
0
1
1
12
0
6
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Nuxt.
- CVE-2026-71321Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation7.5
- CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props8.1
- CVE-2026-71318Nuxt: Unauthorized Component Instantiation via Server Island Props4.8
- CVE-2026-71316Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients7.5
- CVE-2026-71315Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)8.2
- CVE-2026-71314Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering7.5
- CVE-2026-56301Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux5.5
- CVE-2026-56698Nuxt - Cross-Site Scripting via navigateTo open Option6.1
- CVE-2026-56697Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp6.1
- CVE-2026-56326Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo6.1
- CVE-2026-56317Nuxt - Cross-Site Scripting via NoScript Component Slot Content6.1
- CVE-2026-53722Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL5.4
- CVE-2026-53721Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher8.2
- CVE-2026-47200Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`5.3
- CVE-2026-49993@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)5.7
Product normalization is registry-driven with AI assist and human review. How it works