CVE-2026-56326
- EPSS 0.36%
- Veröffentlicht 22.06.2026 21:04:50
- Zuletzt bearbeitet 25.06.2026 16:51:17
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host ch...
CVE-2026-56317
- EPSS 0.36%
- Veröffentlicht 20.06.2026 15:21:56
- Zuletzt bearbeitet 24.06.2026 19:17:13
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoSc...
CVE-2026-53722
- EPSS 0.2%
- Veröffentlicht 12.06.2026 13:44:14
- Zuletzt bearbeitet 15.06.2026 02:10:42
Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> el...
CVE-2026-53721
- EPSS 0.29%
- Veröffentlicht 12.06.2026 13:41:34
- Zuletzt bearbeitet 15.06.2026 02:11:03
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This is...
CVE-2026-47200
- EPSS 0.23%
- Veröffentlicht 12.06.2026 12:58:00
- Zuletzt bearbeitet 15.06.2026 18:09:33
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experimental.compo...
CVE-2026-49993
- EPSS 0.28%
- Veröffentlicht 12.06.2026 12:57:43
- Zuletzt bearbeitet 15.06.2026 18:10:01
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still ...
CVE-2026-45669
- EPSS 0.18%
- Veröffentlicht 12.06.2026 12:51:42
- Zuletzt bearbeitet 15.06.2026 18:09:37
Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redirect body containing a <meta http-equiv="refresh"> ...
CVE-2026-45670
- EPSS 0.21%
- Veröffentlicht 12.06.2026 12:51:16
- Zuletzt bearbeitet 15.06.2026 18:08:40
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be...
CVE-2026-46342
- EPSS 0.09%
- Veröffentlicht 12.06.2026 12:50:41
- Zuletzt bearbeitet 15.06.2026 18:09:23
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_island/* end...
CVE-2025-59414
- EPSS 0.37%
- Veröffentlicht 17.09.2025 18:39:38
- Zuletzt bearbeitet 03.12.2025 18:47:40
Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vulnerability in Nuxt's Island payload revival mechanism allowed attackers to manipulate client-side requests to different endpoints ...