Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
14 Total advisories
14 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.3
npm

CVE-2026-47200

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

MEDIUM 5.4
npm

CVE-2026-46342

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

MEDIUM 5.4
npm

CVE-2026-45669

Nuxt: Reflected XSS in `navigateTo()` external redirect

MEDIUM 5.5
npm

CVE-2026-56301

Nuxt dev server vite-node IPC socket is world-connectable on Linux

UNKNOWN
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

UNKNOWN
npm

CVE-2026-56317

Cross-site scripting via <NoScript> slot content in Nuxt's head components

UNKNOWN
npm

CVE-2026-53721

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

UNKNOWN
npm

CVE-2026-53722

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

UNKNOWN
npm

GHSA-rq7w-g337-39qq

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

LOW 3.1
npm

CVE-2025-59414

Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival

MEDIUM 6.3
npm

CVE-2024-34343

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

HIGH 7.5
npm

CVE-2025-27415

Nuxt allows DOS via cache poisoning with payload rendering response

HIGH 8.8
npm

CVE-2024-34344

Nuxt vulnerable to remote code execution via the browser when running the test locally

HIGH 8.1
npm

CVE-2023-3224

nuxt Code Injection vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes