Vulnerabilidades en Nuxt
30 resultadosAnálisis Vexday
O Nuxt apresenta 5 vulnerabilidades registradas, todas publicadas nos últimos 90 dias, indicando risco emergente. Nenhuma está sob ataque ativo conhecido ou classificada como crítica, mas a concentração em CWE-601 (Open Redirect) aponta para uma fraqueza específica que requer atenção em validação de redirecionamentos. O panorama sugere vulnerabilidades de severidade baixa a média, porém recentes.
CVE-2026-49993MEDIUM@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)EPSS 0.3%CVE-2026-71315HIGHNuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)EPSS 0.3%CVE-2026-47200MEDIUMNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`EPSS 0.2%CVE-2026-56317LOWNuxt - Cross-Site Scripting via NoScript Component Slot ContentEPSS 0.2%CVE-2026-71318MEDIUMNuxt: Unauthorized Component Instantiation via Server Island PropsEPSS 0.2%CVE-2026-45670MEDIUMNuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)EPSS 0.2%CVE-2026-53722MEDIUMNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URLEPSS 0.2%CVE-2026-45669MEDIUMNuxt: Reflected XSS in `navigateTo()` external redirectEPSS 0.2%CVE-2026-56301MEDIUMNuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on LinuxEPSS 0.1%CVE-2026-46342LOWNuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoningEPSS 0.1%