Nuxt

Nuxt

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 23.06.2026 12:13:02
  • Zuletzt bearbeitet 25.06.2026 18:39:47

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and conn...

  • EPSS 0.23%
  • Veröffentlicht 22.06.2026 21:04:53
  • Zuletzt bearbeitet 25.06.2026 16:56:19

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary sc...

  • EPSS 0.19%
  • Veröffentlicht 22.06.2026 21:04:53
  • Zuletzt bearbeitet 25.06.2026 16:55:20

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attacker...

  • EPSS 0.21%
  • Veröffentlicht 22.06.2026 21:04:50
  • Zuletzt bearbeitet 25.06.2026 16:51:17

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host ch...

  • EPSS 0.36%
  • Veröffentlicht 20.06.2026 15:21:56
  • Zuletzt bearbeitet 24.06.2026 19:17:13

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoSc...

  • EPSS 0.2%
  • Veröffentlicht 12.06.2026 13:44:14
  • Zuletzt bearbeitet 15.06.2026 02:10:42

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> el...

  • EPSS 0.29%
  • Veröffentlicht 12.06.2026 13:41:34
  • Zuletzt bearbeitet 15.06.2026 02:11:03

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This is...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 12:58:00
  • Zuletzt bearbeitet 15.06.2026 18:09:33

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experimental.compo...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 12.06.2026 12:57:43
  • Zuletzt bearbeitet 15.06.2026 18:10:01

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still ...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 12.06.2026 12:51:42
  • Zuletzt bearbeitet 15.06.2026 18:09:37

Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redirect body containing a <meta http-equiv="refresh"> ...