Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Quelle: GitHub Advisory Database, stündlich abgerufen. · Zuletzt geprüft 21.09.2026
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
Nuxt: Unauthorized Component Instantiation via Server Island Props
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
Cross-site scripting via <NoScript> slot content in Nuxt's head components
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Nuxt: Reflected XSS in `navigateTo()` external redirect
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Nuxt allows DOS via cache poisoning with payload rendering response
Nuxt vulnerable to remote code execution via the browser when running the test locally
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
nuxt Code Injection vulnerability