Nuxt是Nuxt团队开源的一个免费的开源框架。 Nuxt存在安全漏洞,该漏洞源于在启用experimental.componentIslands时,会注册服务器岛端点,未实例化Vue Router导致路由中间件未执行,可能导致安全策略绕过。以下版本受到影响:3.11.0版本至3.21.6之前版本、4.0.0-alpha.1版本至4.4.6之前版本、@nuxt/nitro-server 3.20.0版本至3.21.6之前版本和4.0.0-alpha.1版本至4.4.6之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53721 | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and th | |
| CVE-2026-53722 | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL | |
| CVE-2026-45669 | Nuxt: Reflected XSS in `navigateTo()` external redirect | |
| CVE-2026-45670 | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA | |
| CVE-2026-49993 | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when | |
| CVE-2026-46342 | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-c |
No comments yet