Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
5 active CVEs reported via OSV.dev
nuxt Code Injection vulnerability
Nuxt allows DOS via cache poisoning with payload rendering response
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Nuxt vulnerable to remote code execution via the browser when running the test locally
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
Other Web Framework projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Nuxt.js โ without relying on volunteer maintainers.
Talk to an Expert โ