OsVault/npm/nuxt
npm1 critical

nuxt

35 known vulnerabilities · 1 critical · 0 high

GHSA-fx6j-w5w5-h468

Nuxt: Reflected XSS in `navigateTo()` external redirect

Published May 19, 2026
GHSA-hg3f-28rg-4jxj

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

Published May 29, 2026
GHSA-rq7w-g337-39qq

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Published Jun 15, 2026
GHSA-g8wj-3cr3-6w7v

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Published May 19, 2026
GHSA-534h-c3cw-v3h9

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Published Jun 16, 2026
GHSA-934w-87qh-qr26

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Published Jun 16, 2026
GHSA-c9cv-mq2m-ppp3

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Published Jun 16, 2026
GHSA-mm7m-92g8-7m47

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Published Jun 16, 2026
GHSA-m3q2-p4fw-w38m

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Published Jun 16, 2026
MAL-2025-191073

Malicious code in better-auth-nuxt (npm)

Published Nov 24, 2025
GHSA-c2rm-g55x-8hr5

nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

Published May 7, 2026
CVE-2025-52662

Nuxt DevTools vulnerable to cross-site scripting (XSS)

Published Nov 7, 2025
MAL-2025-191242

Malicious code in @livecms/nuxt-live-edit (npm)

Published Nov 25, 2025
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
MAL-2025-191243

Malicious code in @lui-ui/lui-nuxt (npm)

Published Nov 24, 2025
MAL-2025-191230

Malicious code in @huntersofbook/core-nuxt (npm)

Published Nov 25, 2025
CVE-2026-34404
Risk: 0.02/100

Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions

Published Mar 31, 2026
CVE-2019-13506MEDIUM

Cross-Site Scripting in @nuxt/devalue

Published Jul 16, 2019
CVE-2026-34405MEDIUM
Risk: 30.51/100

Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes

Published Mar 31, 2026
MAL-2026-795

Malicious code in @opposhop/nuxt-ssr-cache (npm)

Published Feb 6, 2026
CVE-2023-2138CRITICAL

@nuxtlabs/github-module made Use of Hard-coded Credentials

Published Apr 18, 2023
CVE-2025-24360

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

Published Jan 27, 2025
MAL-2025-191267

Malicious code in @oku-ui/primitives-nuxt (npm)

Published Nov 25, 2025
MAL-2025-190749

Malicious code in @posthog/nuxt (npm)

Published Nov 24, 2025
MAL-2026-2585

Malicious code in @hrb-web/nuxt (npm)

Published Apr 13, 2026
MAL-2026-4444

Malicious code in @shwfed/nuxt (npm)

Published May 22, 2026
MAL-2025-4725

Malicious code in frontegg-nuxt-example (npm)

Published Jun 9, 2025
MAL-2025-191185

Malicious code in @alexcolls/nuxt-socket.io (npm)

Published Nov 25, 2025
MAL-2025-191448

Malicious code in vue-browserupdate-nuxt (npm)

Published Nov 24, 2025
GHSA-6m52-m754-pw2g

Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)

Published May 19, 2026
GHSA-x6qj-4h56-5rj5

@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)

Published Jun 16, 2026
MAL-2025-191186

Malicious code in @alexcolls/nuxt-ux (npm)

Published Nov 25, 2025
MAL-2025-191261

Malicious code in @oku-ui/motion-nuxt (npm)

Published Nov 25, 2025
MAL-2025-191288

Malicious code in @pergel/nuxt (npm)

Published Nov 25, 2025
MAL-2025-191400

Malicious code in nuxt-keycloak (npm)

Published Nov 25, 2025
Check your entire dependency tree at onceRun dependency scan →