Vulnerabilities in nuxt
32 resultsVexday analysis
Nuxt registra 19 vulnerabilidades na base, com 7 publicadas nos últimos 90 dias, sinalizando atividade recente de descobertas. Não há exploração ativa documentada (KEV) nem vulnerabilidades críticas, reduzindo a urgência imediata. A fraqueza dominante é XSS (CWE-79), tipicamente de risco moderado em frameworks frontend, exigindo validação de entrada e sanitização em aplicações.
CVE-2023-3224HIGHCode Injection in nuxt/nuxtEPSS 58.6%CVE-2024-23657HIGHPath Traversal: '../filedir' in Nuxt DevtoolsEPSS 1.2%CVE-2024-34344HIGHRemote code execution via the browser when running the test locally in nuxtEPSS 0.8%CVE-2026-71321HIGHNuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validationEPSS 0.7%CVE-2026-71320HIGHNuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island PropsEPSS 0.7%CVE-2026-71314HIGHNuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingEPSS 0.7%CVE-2024-42352HIGHServer-Side Request Forgery (SSRF) in nuxt-iconEPSS 0.6%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.6%CVE-2025-24360MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.5%CVE-2023-0878MEDIUMCross-site Scripting (XSS) - Generic in nuxt/frameworkEPSS 0.5%CVE-2022-4413MEDIUMCross-site Scripting (XSS) - Reflected in nuxt/frameworkEPSS 0.5%CVE-2026-53721HIGHNuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcherEPSS 0.5%CVE-2026-71316HIGHNuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsEPSS 0.5%CVE-2026-71315HIGHNuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)EPSS 0.5%CVE-2022-4414MEDIUMCross-site Scripting (XSS) - DOM in nuxt/frameworkEPSS 0.5%CVE-2024-34343MEDIUMCross-site Scripting (XSS) in navigateTo if used after SSR in nuxtEPSS 0.4%CVE-2026-56698MEDIUMNuxt - Cross-Site Scripting via navigateTo open OptionEPSS 0.4%CVE-2025-27415HIGHNuxt allows DOS via cache poisoning with payload rendering responseEPSS 0.4%CVE-2025-59414LOWNuxt Client-Side Path Traversal in Nuxt Island Payload RevivalEPSS 0.4%CVE-2026-45670MEDIUMNuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)EPSS 0.4%