pwnmyvibecode_

Nuxt and Vue vulnerabilities and security advisories

The newest reviewed advisories for nuxt and vue on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.

Get an email when Nuxt and Vue has a new one

Email alerts are coming soon. This page updates every hour.

$ latest 22 · 9 critical, high or exploited

  • mediumAug 7, 2026

    Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

    • nuxt >= 4.4.7, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.21.7, < 3.21.10 · fixed in 3.21.10
    GHSA-7c4v-fwgw-9rf7CVE-2026-72744
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-7c4v-fwgw-9rf7 (CVE-2026-72744), severity medium
    What it is: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
    Affected packages:
    - nuxt: affected versions >= 4.4.7, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.21.7, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-7c4v-fwgw-9rf7
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highAug 5, 2026

    Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

    • nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
    GHSA-9pgf-384g-p7mvCVE-2026-71321
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-9pgf-384g-p7mv (CVE-2026-71321), severity high
    What it is: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-9pgf-384g-p7mv
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highAug 5, 2026

    Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

    • nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.4.0, < 3.21.10 · fixed in 3.21.10
    GHSA-9473-5f9j-94wqCVE-2026-71320
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-9473-5f9j-94wq (CVE-2026-71320), severity high
    What it is: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.4.0, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-9473-5f9j-94wq
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumAug 5, 2026

    Nuxt: Unauthorized Component Instantiation via Server Island Props

    • nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
    GHSA-48hr-524c-v5w3CVE-2026-71318
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-48hr-524c-v5w3 (CVE-2026-71318), severity medium
    What it is: Nuxt: Unauthorized Component Instantiation via Server Island Props
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-48hr-524c-v5w3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highAug 5, 2026

    Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

    • nuxt >= 4.4.0, <= 4.5.0 · fixed in 4.5.1
    GHSA-wm8w-6qjm-cv43CVE-2026-71316
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-wm8w-6qjm-cv43 (CVE-2026-71316), severity high
    What it is: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
    Affected packages:
    - nuxt: affected versions >= 4.4.0, <= 4.5.0. Fixed in 4.5.1.
    Details: https://github.com/advisories/GHSA-wm8w-6qjm-cv43
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highAug 5, 2026

    Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

    • nuxt >= 4.4.7, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.21.7, < 3.21.10 · fixed in 3.21.10
    GHSA-hxvh-4h3w-prp9CVE-2026-71315
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hxvh-4h3w-prp9 (CVE-2026-71315), severity high
    What it is: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
    Affected packages:
    - nuxt: affected versions >= 4.4.7, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.21.7, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-hxvh-4h3w-prp9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highAug 5, 2026

    Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

    • nuxt >= 4.0.0, < 4.5.1 · fixed in 4.5.1
    • nuxt >= 3.1.0, < 3.21.10 · fixed in 3.21.10
    GHSA-hxcr-hm88-mpq6CVE-2026-71314
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hxcr-hm88-mpq6 (CVE-2026-71314), severity high
    What it is: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.5.1. Fixed in 4.5.1.
    - nuxt: affected versions >= 3.1.0, < 3.21.10. Fixed in 3.21.10.
    Details: https://github.com/advisories/GHSA-hxcr-hm88-mpq6
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowJun 16, 2026

    Cross-site scripting via <NoScript> slot content in Nuxt's head components

    • nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
    • nuxt < 3.21.7 · fixed in 3.21.7
    GHSA-m3q2-p4fw-w38mCVE-2026-56317
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-m3q2-p4fw-w38m (CVE-2026-56317), severity low
    What it is: Cross-site scripting via <NoScript> slot content in Nuxt's head components
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7.
    - nuxt: affected versions < 3.21.7. Fixed in 3.21.7.
    Details: https://github.com/advisories/GHSA-m3q2-p4fw-w38m
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJun 16, 2026

    Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

    • nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
    • nuxt >= 3.0.0, < 3.21.7 · fixed in 3.21.7
    GHSA-934w-87qh-qr26CVE-2026-53722
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-934w-87qh-qr26 (CVE-2026-53722), severity medium
    What it is: Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7.
    - nuxt: affected versions >= 3.0.0, < 3.21.7. Fixed in 3.21.7.
    Details: https://github.com/advisories/GHSA-934w-87qh-qr26
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJun 16, 2026

    Nuxt dev server vite-node IPC socket is world-connectable on Linux

    • nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
    • nuxt >= 3.18.0, < 3.21.7 · fixed in 3.21.7
    GHSA-534h-c3cw-v3h9CVE-2026-56301
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-534h-c3cw-v3h9 (CVE-2026-56301), severity medium
    What it is: Nuxt dev server vite-node IPC socket is world-connectable on Linux
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7.
    - nuxt: affected versions >= 3.18.0, < 3.21.7. Fixed in 3.21.7.
    Details: https://github.com/advisories/GHSA-534h-c3cw-v3h9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 16, 2026

    Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

    • nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
    • nuxt >= 3.11.0, < 3.21.7 · fixed in 3.21.7
    GHSA-mm7m-92g8-7m47CVE-2026-53721
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-mm7m-92g8-7m47 (CVE-2026-53721), severity high
    What it is: Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7.
    - nuxt: affected versions >= 3.11.0, < 3.21.7. Fixed in 3.21.7.
    Details: https://github.com/advisories/GHSA-mm7m-92g8-7m47
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJun 16, 2026

    Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

    • nuxt >= 4.0.0, < 4.4.7 · fixed in 4.4.7
    • nuxt >= 3.5.0, < 3.21.7 · fixed in 3.21.7
    GHSA-c9cv-mq2m-ppp3CVE-2026-56326
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-c9cv-mq2m-ppp3 (CVE-2026-56326), severity medium
    What it is: Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
    Affected packages:
    - nuxt: affected versions >= 4.0.0, < 4.4.7. Fixed in 4.4.7.
    - nuxt: affected versions >= 3.5.0, < 3.21.7. Fixed in 3.21.7.
    Details: https://github.com/advisories/GHSA-c9cv-mq2m-ppp3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowJun 15, 2026

    Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

    • nuxt >= 4.0.0-alpha.1, < 4.4.7 · fixed in 4.4.7
    GHSA-rq7w-g337-39qq
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-rq7w-g337-39qq, severity low
    What it is: Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
    Affected packages:
    - nuxt: affected versions >= 4.0.0-alpha.1, < 4.4.7. Fixed in 4.4.7.
    Details: https://github.com/advisories/GHSA-rq7w-g337-39qq
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 29, 2026

    Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

    • nuxt >= 3.11.0, <= 3.21.5 · fixed in 3.21.6
    • nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
    GHSA-hg3f-28rg-4jxjCVE-2026-47200
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hg3f-28rg-4jxj (CVE-2026-47200), severity medium
    What it is: Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
    Affected packages:
    - nuxt: affected versions >= 3.11.0, <= 3.21.5. Fixed in 3.21.6.
    - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6.
    Details: https://github.com/advisories/GHSA-hg3f-28rg-4jxj
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowMay 19, 2026

    Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

    • nuxt >= 3.1.0, <= 3.21.5 · fixed in 3.21.6
    • nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
    GHSA-g8wj-3cr3-6w7vCVE-2026-46342
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-g8wj-3cr3-6w7v (CVE-2026-46342), severity low
    What it is: Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
    Affected packages:
    - nuxt: affected versions >= 3.1.0, <= 3.21.5. Fixed in 3.21.6.
    - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6.
    Details: https://github.com/advisories/GHSA-g8wj-3cr3-6w7v
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 19, 2026

    Nuxt: Reflected XSS in `navigateTo()` external redirect

    • nuxt >= 3.4.3, <= 3.21.5 · fixed in 3.21.6
    • nuxt >= 4.0.0-alpha.1, <= 4.4.5 · fixed in 4.4.6
    GHSA-fx6j-w5w5-h468CVE-2026-45669
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-fx6j-w5w5-h468 (CVE-2026-45669), severity medium
    What it is: Nuxt: Reflected XSS in `navigateTo()` external redirect
    Affected packages:
    - nuxt: affected versions >= 3.4.3, <= 3.21.5. Fixed in 3.21.6.
    - nuxt: affected versions >= 4.0.0-alpha.1, <= 4.4.5. Fixed in 4.4.6.
    Details: https://github.com/advisories/GHSA-fx6j-w5w5-h468
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowSep 17, 2025

    Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival

    • nuxt >= 3.6.0, < 3.19.0 · fixed in 3.19.0
    • nuxt >= 4.0.0, < 4.1.0 · fixed in 4.1.0
    GHSA-p6jq-8vc4-79f6CVE-2025-59414
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-p6jq-8vc4-79f6 (CVE-2025-59414), severity low
    What it is: Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
    Affected packages:
    - nuxt: affected versions >= 3.6.0, < 3.19.0. Fixed in 3.19.0.
    - nuxt: affected versions >= 4.0.0, < 4.1.0. Fixed in 4.1.0.
    Details: https://github.com/advisories/GHSA-p6jq-8vc4-79f6
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMar 19, 2025

    Nuxt allows DOS via cache poisoning with payload rendering response

    • nuxt >= 3.0.0, < 3.16.0 · fixed in 3.16.0
    GHSA-jvhm-gjrh-3h93CVE-2025-27415
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-jvhm-gjrh-3h93 (CVE-2025-27415), severity high
    What it is: Nuxt allows DOS via cache poisoning with payload rendering response
    Affected packages:
    - nuxt: affected versions >= 3.0.0, < 3.16.0. Fixed in 3.16.0.
    Details: https://github.com/advisories/GHSA-jvhm-gjrh-3h93
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowOct 15, 2024

    ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

    • vue >= 2.0.0-alpha.1, < 3.0.0-alpha.0 · fixed in 3.0.0-alpha.0
    GHSA-5j4c-8p2g-v4jxCVE-2024-9506
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-5j4c-8p2g-v4jx (CVE-2024-9506), severity low
    What it is: ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
    Affected packages:
    - vue: affected versions >= 2.0.0-alpha.1, < 3.0.0-alpha.0. Fixed in 3.0.0-alpha.0.
    Details: https://github.com/advisories/GHSA-5j4c-8p2g-v4jx
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • criticalAug 5, 2024

    Nuxt vulnerable to remote code execution via the browser when running the test locally

    • nuxt >= 3.4.0, < 3.12.4 · fixed in 3.12.4
    GHSA-v784-fjjh-f8r4CVE-2024-34344
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-v784-fjjh-f8r4 (CVE-2024-34344), severity critical
    What it is: Nuxt vulnerable to remote code execution via the browser when running the test locally
    Affected packages:
    - nuxt: affected versions >= 3.4.0, < 3.12.4. Fixed in 3.12.4.
    Details: https://github.com/advisories/GHSA-v784-fjjh-f8r4
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumAug 5, 2024

    nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

    • nuxt < 3.12.4 · fixed in 3.12.4
    GHSA-vf6r-87q4-2vjfCVE-2024-34343
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-vf6r-87q4-2vjf (CVE-2024-34343), severity medium
    What it is: nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
    Affected packages:
    - nuxt: affected versions < 3.12.4. Fixed in 3.12.4.
    Details: https://github.com/advisories/GHSA-vf6r-87q4-2vjf
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • criticalJun 13, 2023

    nuxt Code Injection vulnerability

    • nuxt >= 3.4.0, < 3.4.3 · fixed in 3.4.3
    GHSA-gc34-5v43-h7v8CVE-2023-3224
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-gc34-5v43-h7v8 (CVE-2023-3224), severity critical
    What it is: nuxt Code Injection vulnerability
    Affected packages:
    - nuxt: affected versions >= 3.4.0, < 3.4.3. Fixed in 3.4.3.
    Details: https://github.com/advisories/GHSA-gc34-5v43-h7v8
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.

From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.

Keeping Nuxt and Vue patched

  • npm audit (or pnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.
  • Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
  • A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.