OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v4.5.2

Nuxt.js

Intuitive Vue framework for building full-stack applications

Project Health at a Glance

Live data from GitHub and npm, updated daily.

60.8K+97
GitHub Stars
📦
v4.5.2
Latest Release · 19 days ago
🔄
7d
Avg. Release Cadence
🐛
540
Open Issues
📅
Today
Last Commit
⬇️
1.9M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-08-24

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Nuxt: Unauthorized Component Instantiation via Server Island Props

Published: 2026-08-05 Fixed in: 4.5.1

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Published: 2026-08-07 Fixed in: 4.5.1

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Published: 2026-08-05 Fixed in: 4.5.1

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

Published: 2026-08-05 Fixed in: 4.5.1

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: Reflected XSS in `navigateTo()` external redirect

Published: 2026-05-19 Fixed in: 3.21.6

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Published: 2026-05-19 Fixed in: 3.21.6

nuxt Code Injection vulnerability

Published: 2023-06-13 Fixed in: 3.4.3

Alternatives to Nuxt.js

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Nuxt.js

Commercial Support from DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Nuxt.js — without relying on volunteer maintainers.