22 Total advisories
22 Vulnerabilities
0 Malware

Dependency scanning

Check whether nuxt is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.1
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

UNKNOWN
npm

CVE-2026-53722

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

MEDIUM 6.2
npm

GHSA-4jjw-pwvw-q6w3

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

UNKNOWN
npm

CVE-2026-72744

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

HIGH 7.5
npm

CVE-2026-71321

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

HIGH 8.1
npm

CVE-2026-71320

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

MEDIUM 4.8
npm

CVE-2026-71318

Nuxt: Unauthorized Component Instantiation via Server Island Props

HIGH 7.5
npm

CVE-2026-71316

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

HIGH 8.2
npm

CVE-2026-71315

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

HIGH 7.5
npm

CVE-2026-71314

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

MEDIUM 5.3
npm

CVE-2026-47200

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

MEDIUM 5.4
npm

CVE-2026-46342

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

MEDIUM 5.4
npm

CVE-2026-45669

Nuxt: Reflected XSS in `navigateTo()` external redirect

MEDIUM 5.5
npm

CVE-2026-56301

Nuxt dev server vite-node IPC socket is world-connectable on Linux

UNKNOWN
npm

CVE-2026-56317

Cross-site scripting via <NoScript> slot content in Nuxt's head components

UNKNOWN
npm

CVE-2026-53721

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

UNKNOWN
npm

GHSA-rq7w-g337-39qq

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

LOW 3.1
npm

CVE-2025-59414

Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival

MEDIUM 6.3
npm

CVE-2024-34343

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

HIGH 7.5
npm

CVE-2025-27415

Nuxt allows DOS via cache poisoning with payload rendering response

HIGH 8.8
npm

CVE-2024-34344

Nuxt vulnerable to remote code execution via the browser when running the test locally

HIGH 8.1
npm

CVE-2023-3224

nuxt Code Injection vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes