OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v4.4.8

Nuxt.js

Intuitive Vue framework for building full-stack applications

Project Health at a Glance

Live data from GitHub and npm, updated daily.

60.5K+238
GitHub Stars
📦
v4.4.8
Latest Release · 21 days ago
🔄
4d
Avg. Release Cadence
🐛
804
Open Issues
📅
Today
Last Commit
⬇️
1.6M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: Reflected XSS in `navigateTo()` external redirect

Published: 2026-05-19 Fixed in: 3.21.6

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Published: 2026-05-19 Fixed in: 3.21.6

nuxt Code Injection vulnerability

Published: 2023-06-13 Fixed in: 3.4.3

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

Published: 2026-05-29 Fixed in: 3.21.6

Nuxt allows DOS via cache poisoning with payload rendering response

Published: 2025-03-19 Fixed in: 3.16.0

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Published: 2026-06-16 Fixed in: 4.4.7

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Published: 2026-06-16 Fixed in: 4.4.7

Alternatives to Nuxt.js

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Nuxt.js

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Nuxt.js — without relying on volunteer maintainers.