Live data from GitHub and npm, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
Nuxt: Unauthorized Component Instantiation via Server Island Props
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Nuxt: Reflected XSS in `navigateTo()` external redirect
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
nuxt Code Injection vulnerability
Get SLA-backed support, security patches, and direct access to senior engineers for Nuxt.js — without relying on volunteer maintainers.