nuxt
Nuxt is a free and open-source framework with an intuitive and extendable way to create type-safe, performant and production-grade full-stack web applications and websites with Vue.js.
Security Advisories for nuxt in npm
Moderate
3 days ago
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
npm
nuxt
High
5 days ago
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
npm
nuxt
High
5 days ago
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
npm
nuxt
Low
about 2 months ago
Cross-site scripting via <NoScript> slot content in Nuxt's head components
npm
nuxt
Moderate
about 2 months ago
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
npm
nuxt
Moderate
about 2 months ago
Nuxt dev server vite-node IPC socket is world-connectable on Linux
npm
nuxt
High
about 2 months ago
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
npm
nuxt
Moderate
2 months ago
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
npm
nuxt, @nuxt/nitro-server
Low
3 months ago
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
npm
@nuxt/nitro-server, nuxt
Potential
Moderate
over 1 year ago
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
npm
@nuxt/rspack-builder, @nuxt/webpack-builder
Potential
Moderate
over 1 year ago
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
npm
@nuxt/vite-builder
Critical
about 2 years ago
Nuxt vulnerable to remote code execution via the browser when running the test locally
npm
nuxt
Moderate
about 2 years ago
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
npm
nuxt
Potential