Security changelog

Nuxt

23 fixes · 9 high/critical

Source: GitHub Advisory Database, pulled hourly. · Last checked Sep 21, 2026

Aug 2026

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Affected: >= 4.4.7, < 4.5.1
mediumGHSA-7c4v-fwgw-9rf7CVE-2026-72744
Aug 2026

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Affected: >= 4.4.7, < 4.5.1 · >= 3.21.7, < 3.21.10Fixed in 4.5.1, 3.21.10
highGHSA-9pgf-384g-p7mvCVE-2026-71321
Aug 2026

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

Affected: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Fixed in 4.5.1, 3.21.10
highGHSA-9473-5f9j-94wqCVE-2026-71320
Aug 2026

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Affected: >= 4.0.0, < 4.5.1 · >= 3.4.0, < 3.21.10Fixed in 4.5.1, 3.21.10
mediumGHSA-48hr-524c-v5w3CVE-2026-71318
Aug 2026

Nuxt: Unauthorized Component Instantiation via Server Island Props

Affected: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Fixed in 4.5.1, 3.21.10
highGHSA-wm8w-6qjm-cv43CVE-2026-71316
Aug 2026

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

Affected: >= 4.4.0, <= 4.5.0Fixed in 4.5.1
highGHSA-hxvh-4h3w-prp9CVE-2026-71315
Aug 2026

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

Affected: >= 4.4.7, < 4.5.1 · >= 3.21.7, < 3.21.10Fixed in 4.5.1, 3.21.10
highGHSA-hxcr-hm88-mpq6CVE-2026-71314
Aug 2026

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

Affected: >= 4.0.0, < 4.5.1 · >= 3.1.0, < 3.21.10Fixed in 4.5.1, 3.21.10

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Affected: >= 4.0.0, < 4.4.7 · < 3.21.7Fixed in 4.4.7, 3.21.7
lowGHSA-m3q2-p4fw-w38mCVE-2026-56317
Jun 2026

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Affected: >= 4.0.0, < 4.4.7 · < 3.21.7Fixed in 4.4.7, 3.21.7
Show all 13
mediumGHSA-934w-87qh-qr26CVE-2026-53722
Jun 2026

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Affected: >= 4.0.0, < 4.4.7 · >= 3.0.0, < 3.21.7Fixed in 4.4.7, 3.21.7
Jun 2026

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Affected: >= 4.0.0, < 4.4.7 · >= 3.18.0, < 3.21.7Fixed in 4.4.7, 3.21.7
highGHSA-mm7m-92g8-7m47CVE-2026-53721
Jun 2026

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Affected: >= 4.0.0, < 4.4.7 · >= 3.11.0, < 3.21.7Fixed in 4.4.7, 3.21.7
mediumGHSA-c9cv-mq2m-ppp3CVE-2026-56326
Jun 2026

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Affected: >= 4.0.0, < 4.4.7 · >= 3.5.0, < 3.21.7Fixed in 4.4.7, 3.21.7

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Affected: >= 4.0.0-alpha.1, < 4.4.7Fixed in 4.4.7
mediumGHSA-hg3f-28rg-4jxjCVE-2026-47200
May 2026

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

Affected: >= 3.11.0, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Fixed in 3.21.6, 4.4.6
lowGHSA-g8wj-3cr3-6w7vCVE-2026-46342
May 2026

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Affected: >= 3.1.0, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Fixed in 3.21.6, 4.4.6
mediumGHSA-fx6j-w5w5-h468CVE-2026-45669
May 2026

Nuxt: Reflected XSS in `navigateTo()` external redirect

Affected: >= 3.4.3, <= 3.21.5 · >= 4.0.0-alpha.1, <= 4.4.5Fixed in 3.21.6, 4.4.6
lowGHSA-p6jq-8vc4-79f6CVE-2025-59414
Sep 2025

Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival

Affected: >= 3.6.0, < 3.19.0 · >= 4.0.0, < 4.1.0Fixed in 3.19.0, 4.1.0
highGHSA-jvhm-gjrh-3h93CVE-2025-27415
Mar 2025

Nuxt allows DOS via cache poisoning with payload rendering response

Affected: >= 3.0.0, < 3.16.0Fixed in 3.16.0
criticalGHSA-v784-fjjh-f8r4CVE-2024-34344
Aug 2024

Nuxt vulnerable to remote code execution via the browser when running the test locally

Affected: >= 3.4.0, < 3.12.4Fixed in 3.12.4
mediumGHSA-vf6r-87q4-2vjfCVE-2024-34343
Aug 2024

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

Affected: < 3.12.4Fixed in 3.12.4
criticalGHSA-gc34-5v43-h7v8CVE-2023-3224
Jun 2023

nuxt Code Injection vulnerability

Affected: >= 3.4.0, < 3.4.3Fixed in 3.4.3