Vulnerabilities in Nuxt

32 results
Vexday analysis

O Nuxt apresenta 5 vulnerabilidades registradas, todas publicadas nos últimos 90 dias, indicando risco emergente. Nenhuma está sob ataque ativo conhecido ou classificada como crítica, mas a concentração em CWE-601 (Open Redirect) aponta para uma fraqueza específica que requer atenção em validação de redirecionamentos. O panorama sugere vulnerabilidades de severidade baixa a média, porém recentes.

CVE-2023-3224HIGHCode Injection in nuxt/nuxtEPSS 58.6%CVE-2024-23657HIGHPath Traversal: '../filedir' in Nuxt DevtoolsEPSS 1.2%CVE-2024-34344HIGHRemote code execution via the browser when running the test locally in nuxtEPSS 0.8%CVE-2024-42352HIGHServer-Side Request Forgery (SSRF) in nuxt-iconEPSS 0.6%CVE-2025-24360MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.5%CVE-2023-0878MEDIUMCross-site Scripting (XSS) - Generic in nuxt/frameworkEPSS 0.5%CVE-2022-4413MEDIUMCross-site Scripting (XSS) - Reflected in nuxt/frameworkEPSS 0.5%CVE-2022-4414MEDIUMCross-site Scripting (XSS) - DOM in nuxt/frameworkEPSS 0.4%CVE-2024-34343MEDIUMCross-site Scripting (XSS) in navigateTo if used after SSR in nuxtEPSS 0.4%CVE-2026-71320HIGHNuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island PropsEPSS 0.4%CVE-2026-71321HIGHNuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validationEPSS 0.4%CVE-2026-56698MEDIUMNuxt - Cross-Site Scripting via navigateTo open OptionEPSS 0.4%CVE-2026-71314HIGHNuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingEPSS 0.4%CVE-2025-27415HIGHNuxt allows DOS via cache poisoning with payload rendering responseEPSS 0.4%CVE-2026-56326MEDIUMNuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateToEPSS 0.4%CVE-2025-59414LOWNuxt Client-Side Path Traversal in Nuxt Island Payload RevivalEPSS 0.3%CVE-2026-56697MEDIUMNuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtAppEPSS 0.3%CVE-2025-24361MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.3%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.3%CVE-2026-71316HIGHNuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsEPSS 0.3%