Dependency scanning
Check whether nuxt is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-56326
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-53722
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
GHSA-4jjw-pwvw-q6w3
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
CVE-2026-72744
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
CVE-2026-71321
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
CVE-2026-71320
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
CVE-2026-71318
Nuxt: Unauthorized Component Instantiation via Server Island Props
CVE-2026-71316
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
CVE-2026-71315
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
CVE-2026-71314
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
CVE-2026-47200
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
CVE-2026-46342
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVE-2026-45669
Nuxt: Reflected XSS in `navigateTo()` external redirect
CVE-2026-56301
Nuxt dev server vite-node IPC socket is world-connectable on Linux
CVE-2026-56317
Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-53721
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
GHSA-rq7w-g337-39qq
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
CVE-2025-59414
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
CVE-2024-34343
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
CVE-2025-27415
Nuxt allows DOS via cache poisoning with payload rendering response
CVE-2024-34344
Nuxt vulnerable to remote code execution via the browser when running the test locally
CVE-2023-3224
nuxt Code Injection vulnerability
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes