Security-Changelog

Nuxt

23 Fixes · 9 high/critical

Quelle: GitHub Advisory Database, stündlich abgerufen. · Zuletzt geprüft 21.09.2026

Aug. 2026

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Betroffen: >= 4.4.7, < 4.5.1
mediumGHSA-7c4v-fwgw-9rf7CVE-2026-72744
Aug. 2026

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Betroffen: >= 4.4.7, < 4.5.1 · >= 3.21.7, < 3.21.10Behoben in 4.5.1, 3.21.10
highGHSA-9pgf-384g-p7mvCVE-2026-71321
Aug. 2026

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

Betroffen: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Behoben in 4.5.1, 3.21.10
highGHSA-9473-5f9j-94wqCVE-2026-71320
Aug. 2026

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Betroffen: >= 4.0.0, < 4.5.1 · >= 3.4.0, < 3.21.10Behoben in 4.5.1, 3.21.10
mediumGHSA-48hr-524c-v5w3CVE-2026-71318
Aug. 2026

Nuxt: Unauthorized Component Instantiation via Server Island Props

Betroffen: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Behoben in 4.5.1, 3.21.10
highGHSA-wm8w-6qjm-cv43CVE-2026-71316
Aug. 2026

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

Betroffen: >= 4.4.0, <= 4.5.0Behoben in 4.5.1
highGHSA-hxvh-4h3w-prp9CVE-2026-71315
Aug. 2026

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

Betroffen: >= 4.4.7, < 4.5.1 · >= 3.21.7, < 3.21.10Behoben in 4.5.1, 3.21.10
highGHSA-hxcr-hm88-mpq6CVE-2026-71314
Aug. 2026

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

Betroffen: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Behoben in 4.5.1, 3.21.10

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Betroffen: >= 4.0.0, < 4.4.7 · < 3.21.7Behoben in 4.4.7, 3.21.7
lowGHSA-m3q2-p4fw-w38mCVE-2026-56317
Juni 2026

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Betroffen: >= 4.0.0, < 4.4.7 · < 3.21.7Behoben in 4.4.7, 3.21.7
Alle anzeigen 13
mediumGHSA-934w-87qh-qr26CVE-2026-53722
Juni 2026

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Betroffen: >= 4.0.0, < 4.4.7 · >= 3.0.0, < 3.21.7Behoben in 4.4.7, 3.21.7
Juni 2026

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Betroffen: >= 4.0.0, < 4.4.7 · >= 3.18.0, < 3.21.7Behoben in 4.4.7, 3.21.7
highGHSA-mm7m-92g8-7m47CVE-2026-53721
Juni 2026

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Betroffen: >= 4.0.0, < 4.4.7 · >= 3.11.0, < 3.21.7Behoben in 4.4.7, 3.21.7
mediumGHSA-c9cv-mq2m-ppp3CVE-2026-56326
Juni 2026

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Betroffen: >= 4.0.0, < 4.4.7 · >= 3.5.0, < 3.21.7Behoben in 4.4.7, 3.21.7

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Betroffen: >= 4.0.0-alpha.1, < 4.4.7Behoben in 4.4.7
mediumGHSA-hg3f-28rg-4jxjCVE-2026-47200
Mai 2026

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

Betroffen: >= 3.11.0, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Behoben in 3.21.6, 4.4.6
lowGHSA-g8wj-3cr3-6w7vCVE-2026-46342
Mai 2026

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Betroffen: >= 3.1.0, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Behoben in 3.21.6, 4.4.6
mediumGHSA-fx6j-w5w5-h468CVE-2026-45669
Mai 2026

Nuxt: Reflected XSS in `navigateTo()` external redirect

Betroffen: >= 3.4.3, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Behoben in 3.21.6, 4.4.6
lowGHSA-p6jq-8vc4-79f6CVE-2025-59414
Sept. 2025

Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival

Betroffen: >= 3.6.0, < 3.19.0 · >= 4.0.0, < 4.1.0Behoben in 3.19.0, 4.1.0
highGHSA-jvhm-gjrh-3h93CVE-2025-27415
März 2025

Nuxt allows DOS via cache poisoning with payload rendering response

Betroffen: >= 3.0.0, < 3.16.0Behoben in 3.16.0
criticalGHSA-v784-fjjh-f8r4CVE-2024-34344
Aug. 2024

Nuxt vulnerable to remote code execution via the browser when running the test locally

Betroffen: >= 3.4.0, < 3.12.4Behoben in 3.12.4
mediumGHSA-vf6r-87q4-2vjfCVE-2024-34343
Aug. 2024

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

Betroffen: < 3.12.4Behoben in 3.12.4
criticalGHSA-gc34-5v43-h7v8CVE-2023-3224
Juni 2023

nuxt Code Injection vulnerability

Betroffen: >= 3.4.0, < 3.4.3Behoben in 3.4.3