CVEs we hold for Nuxt
Records whose assigning authority named Nuxt as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-71321Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validationnuxt
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsnuxt
CVE-2026-71319Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Executionnuxt devtools
CVE-2026-71316Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsnuxt
CVE-2026-71315Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for…nuxt
CVE-2026-71314Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingnuxt
CVE-2026-63671@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the…nuxt-content mdc
CVE-2026-61793Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameternuxt-modules og-image
CVE-2026-53721Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matchernuxt
CVE-2026-49993@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and…nuxt
CVE-2026-47200Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`nuxt
CVE-2026-46342Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoningnuxt
CVE-2026-45670Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)nuxt
CVE-2026-44589nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)nuxt-modules og-image
CVE-2026-34405Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributesnuxt-modules og-image
CVE-2025-54075mdc vulnerable to XSS in markdown rendering bypassing HTML filter. (N°4)nuxt-modules mdc
CVE-2025-24981Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdcnuxt-modules mdc
CVE-2025-24361Opening a malicious website while running a Nuxt dev server could allow read-only access to codenuxt
CVE-2025-24360Opening a malicious website while running a Nuxt dev server could allow read-only access to codenuxt
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.