Nuxt and Vue vulnerabilities and security advisories
The newest reviewed advisories for nuxt and vue on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.
Get an email when Nuxt and Vue has a new one
Email alerts are coming soon. This page updates every hour.
$ latest 22 · 9 critical, high or exploited
- mediumAug 7, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
- nuxt >= 4.4.7, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.21.7, < 3.21.10 · fixed in 3.21.10
GHSA-7c4v-fwgw-9rf7CVE-2026-72744prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-7c4v-fwgw-9rf7 (CVE-2026-72744), severity medium What it is: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Affected packages: - nuxt: affected versions >= 4.4.7, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.21.7, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-7c4v-fwgw-9rf7 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highAug 5, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
- nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
GHSA-9pgf-384g-p7mvCVE-2026-71321prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9pgf-384g-p7mv (CVE-2026-71321), severity high What it is: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation Affected packages: - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-9pgf-384g-p7mv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highAug 5, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
- nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.4.0, < 3.21.10 · fixed in 3.21.10
GHSA-9473-5f9j-94wqCVE-2026-71320prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9473-5f9j-94wq (CVE-2026-71320), severity high What it is: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props Affected packages: - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.4.0, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-9473-5f9j-94wq Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumAug 5, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
- nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
GHSA-48hr-524c-v5w3CVE-2026-71318prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-48hr-524c-v5w3 (CVE-2026-71318), severity medium What it is: Nuxt: Unauthorized Component Instantiation via Server Island Props Affected packages: - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-48hr-524c-v5w3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highAug 5, 2026
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
- nuxt >= 4.4.0, <= 4.5.0 · fixed in 4.5.1
GHSA-wm8w-6qjm-cv43CVE-2026-71316prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-wm8w-6qjm-cv43 (CVE-2026-71316), severity high What it is: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients Affected packages: - nuxt: affected versions >= 4.4.0, <= 4.5.0. Fixed in 4.5.1. Details: https://github.com/advisories/GHSA-wm8w-6qjm-cv43 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highAug 5, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
- nuxt >= 4.4.7, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.21.7, < 3.21.10 · fixed in 3.21.10
GHSA-hxvh-4h3w-prp9CVE-2026-71315prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hxvh-4h3w-prp9 (CVE-2026-71315), severity high What it is: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) Affected packages: - nuxt: affected versions >= 4.4.7, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.21.7, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-hxvh-4h3w-prp9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highAug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
- nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
- nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
GHSA-hxcr-hm88-mpq6CVE-2026-71314prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hxcr-hm88-mpq6 (CVE-2026-71314), severity high What it is: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering Affected packages: - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1. - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10. Details: https://github.com/advisories/GHSA-hxcr-hm88-mpq6 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJun 16, 2026
Cross-site scripting via <NoScript> slot content in Nuxt's head components
- nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
- nuxt < 3.21.7 · fixed in 3.21.7
GHSA-m3q2-p4fw-w38mCVE-2026-56317prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-m3q2-p4fw-w38m (CVE-2026-56317), severity low What it is: Cross-site scripting via <NoScript> slot content in Nuxt's head components Affected packages: - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7. - nuxt: affected versions < 3.21.7. Fixed in 3.21.7. Details: https://github.com/advisories/GHSA-m3q2-p4fw-w38m Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJun 16, 2026
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
- nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
- nuxt >= 3.0.0, < 3.21.7 · fixed in 3.21.7
GHSA-934w-87qh-qr26CVE-2026-53722prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-934w-87qh-qr26 (CVE-2026-53722), severity medium What it is: Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Affected packages: - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7. - nuxt: affected versions >= 3.0.0, < 3.21.7. Fixed in 3.21.7. Details: https://github.com/advisories/GHSA-934w-87qh-qr26 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJun 16, 2026
Nuxt dev server vite-node IPC socket is world-connectable on Linux
- nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
- nuxt >= 3.18.0, < 3.21.7 · fixed in 3.21.7
GHSA-534h-c3cw-v3h9CVE-2026-56301prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-534h-c3cw-v3h9 (CVE-2026-56301), severity medium What it is: Nuxt dev server vite-node IPC socket is world-connectable on Linux Affected packages: - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7. - nuxt: affected versions >= 3.18.0, < 3.21.7. Fixed in 3.21.7. Details: https://github.com/advisories/GHSA-534h-c3cw-v3h9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 16, 2026
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
- nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
- nuxt >= 3.11.0, < 3.21.7 · fixed in 3.21.7
GHSA-mm7m-92g8-7m47CVE-2026-53721prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-mm7m-92g8-7m47 (CVE-2026-53721), severity high What it is: Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher Affected packages: - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7. - nuxt: affected versions >= 3.11.0, < 3.21.7. Fixed in 3.21.7. Details: https://github.com/advisories/GHSA-mm7m-92g8-7m47 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJun 16, 2026
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
- nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
- nuxt >= 3.5.0, < 3.21.7 · fixed in 3.21.7
GHSA-c9cv-mq2m-ppp3CVE-2026-56326prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-c9cv-mq2m-ppp3 (CVE-2026-56326), severity medium What it is: Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp` Affected packages: - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7. - nuxt: affected versions >= 3.5.0, < 3.21.7. Fixed in 3.21.7. Details: https://github.com/advisories/GHSA-c9cv-mq2m-ppp3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJun 15, 2026
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
- nuxt >= 4.0.0-alpha.1, < 4.4.7 · fixed in 4.4.7
GHSA-rq7w-g337-39qqprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-rq7w-g337-39qq, severity low What it is: Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json` Affected packages: - nuxt: affected versions >= 4.0.0-alpha.1, < 4.4.7. Fixed in 4.4.7. Details: https://github.com/advisories/GHSA-rq7w-g337-39qq Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 29, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
- nuxt >= 3.11.0, <= 3.21.5 · fixed in 3.21.6
- nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
GHSA-hg3f-28rg-4jxjCVE-2026-47200prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hg3f-28rg-4jxj (CVE-2026-47200), severity medium What it is: Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` Affected packages: - nuxt: affected versions >= 3.11.0, <= 3.21.5. Fixed in 3.21.6. - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6. Details: https://github.com/advisories/GHSA-hg3f-28rg-4jxj Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowMay 19, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
- nuxt >= 3.1.0, <= 3.21.5 · fixed in 3.21.6
- nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
GHSA-g8wj-3cr3-6w7vCVE-2026-46342prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-g8wj-3cr3-6w7v (CVE-2026-46342), severity low What it is: Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Affected packages: - nuxt: affected versions >= 3.1.0, <= 3.21.5. Fixed in 3.21.6. - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6. Details: https://github.com/advisories/GHSA-g8wj-3cr3-6w7v Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 19, 2026
Nuxt: Reflected XSS in `navigateTo()` external redirect
- nuxt >= 3.4.3, <= 3.21.5 · fixed in 3.21.6
- nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
GHSA-fx6j-w5w5-h468CVE-2026-45669prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-fx6j-w5w5-h468 (CVE-2026-45669), severity medium What it is: Nuxt: Reflected XSS in `navigateTo()` external redirect Affected packages: - nuxt: affected versions >= 3.4.3, <= 3.21.5. Fixed in 3.21.6. - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6. Details: https://github.com/advisories/GHSA-fx6j-w5w5-h468 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowSep 17, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
- nuxt >= 3.6.0, < 3.19.0 · fixed in 3.19.0
- nuxt >= 4.0.0, < 4.1.0 · fixed in 4.1.0
GHSA-p6jq-8vc4-79f6CVE-2025-59414prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-p6jq-8vc4-79f6 (CVE-2025-59414), severity low What it is: Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival Affected packages: - nuxt: affected versions >= 3.6.0, < 3.19.0. Fixed in 3.19.0. - nuxt: affected versions >= 4.0.0, < 4.1.0. Fixed in 4.1.0. Details: https://github.com/advisories/GHSA-p6jq-8vc4-79f6 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMar 19, 2025
Nuxt allows DOS via cache poisoning with payload rendering response
- nuxt >= 3.0.0, < 3.16.0 · fixed in 3.16.0
GHSA-jvhm-gjrh-3h93CVE-2025-27415prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-jvhm-gjrh-3h93 (CVE-2025-27415), severity high What it is: Nuxt allows DOS via cache poisoning with payload rendering response Affected packages: - nuxt: affected versions >= 3.0.0, < 3.16.0. Fixed in 3.16.0. Details: https://github.com/advisories/GHSA-jvhm-gjrh-3h93 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowOct 15, 2024
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
- vue >= 2.0.0-alpha.1, < 3.0.0-alpha.0 · fixed in 3.0.0-alpha.0
GHSA-5j4c-8p2g-v4jxCVE-2024-9506prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-5j4c-8p2g-v4jx (CVE-2024-9506), severity low What it is: ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function Affected packages: - vue: affected versions >= 2.0.0-alpha.1, < 3.0.0-alpha.0. Fixed in 3.0.0-alpha.0. Details: https://github.com/advisories/GHSA-5j4c-8p2g-v4jx Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - criticalAug 5, 2024
Nuxt vulnerable to remote code execution via the browser when running the test locally
- nuxt >= 3.4.0, < 3.12.4 · fixed in 3.12.4
GHSA-v784-fjjh-f8r4CVE-2024-34344prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-v784-fjjh-f8r4 (CVE-2024-34344), severity critical What it is: Nuxt vulnerable to remote code execution via the browser when running the test locally Affected packages: - nuxt: affected versions >= 3.4.0, < 3.12.4. Fixed in 3.12.4. Details: https://github.com/advisories/GHSA-v784-fjjh-f8r4 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumAug 5, 2024
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
- nuxt < 3.12.4 · fixed in 3.12.4
GHSA-vf6r-87q4-2vjfCVE-2024-34343prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-vf6r-87q4-2vjf (CVE-2024-34343), severity medium What it is: nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR Affected packages: - nuxt: affected versions < 3.12.4. Fixed in 3.12.4. Details: https://github.com/advisories/GHSA-vf6r-87q4-2vjf Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - criticalJun 13, 2023
nuxt Code Injection vulnerability
- nuxt >= 3.4.0, < 3.4.3 · fixed in 3.4.3
GHSA-gc34-5v43-h7v8CVE-2023-3224prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-gc34-5v43-h7v8 (CVE-2023-3224), severity critical What it is: nuxt Code Injection vulnerability Affected packages: - nuxt: affected versions >= 3.4.0, < 3.4.3. Fixed in 3.4.3. Details: https://github.com/advisories/GHSA-gc34-5v43-h7v8 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now.
From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.
Keeping Nuxt and Vue patched
npm audit(orpnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.- Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
- A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.