Vulnerabilities in nuxt
32 resultsVexday analysis
Nuxt registra 19 vulnerabilidades na base, com 7 publicadas nos últimos 90 dias, sinalizando atividade recente de descobertas. Não há exploração ativa documentada (KEV) nem vulnerabilidades críticas, reduzindo a urgência imediata. A fraqueza dominante é XSS (CWE-79), tipicamente de risco moderado em frameworks frontend, exigindo validação de entrada e sanitização em aplicações.
CVE-2026-56326MEDIUMNuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateToEPSS 0.4%CVE-2026-47200MEDIUMNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`EPSS 0.3%CVE-2026-56317LOWNuxt - Cross-Site Scripting via NoScript Component Slot ContentEPSS 0.3%CVE-2025-24361MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.3%CVE-2026-56697MEDIUMNuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtAppEPSS 0.3%CVE-2026-53722MEDIUMNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URLEPSS 0.3%CVE-2026-71318MEDIUMNuxt: Unauthorized Component Instantiation via Server Island PropsEPSS 0.3%CVE-2026-49993MEDIUM@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)EPSS 0.3%CVE-2026-45669MEDIUMNuxt: Reflected XSS in `navigateTo()` external redirectEPSS 0.3%CVE-2026-72744MEDIUMNuxt before 4.5.1 Information Disclosure via Chrome DevToolsEPSS 0.2%CVE-2026-56301MEDIUMNuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on LinuxEPSS 0.1%CVE-2026-46342LOWNuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoningEPSS 0.1%