Nuxt是Nuxt团队开源的一个免费的开源框架。 Nuxt 3.4.3至3.21.6之前版本和4.0.0-alpha.1至4.4.6之前版本存在跨站脚本漏洞,该漏洞源于对 navigateTo() 函数中 URL 的清理不当,仅替换引号而未编码其他特殊字符,可能导致攻击者注入任意 HTML/JavaScript 脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53721 | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and th | |
| CVE-2026-53722 | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL | |
| CVE-2026-45670 | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA | |
| CVE-2026-47200 | Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island | |
| CVE-2026-49993 | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when | |
| CVE-2026-46342 | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-c |
No comments yet