Nuxt是Nuxt团队开源的一个免费的开源框架。 Nuxt 3.11.0至3.21.7之前版本和4.0.0至4.4.7之前版本存在输入验证错误漏洞,该漏洞源于vue-router与routeRules匹配器之间的大小写不匹配,可能导致路由规则中间件绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53722 | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL | |
| CVE-2026-45669 | Nuxt: Reflected XSS in `navigateTo()` external redirect | |
| CVE-2026-45670 | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA | |
| CVE-2026-47200 | Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island | |
| CVE-2026-49993 | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when | |
| CVE-2026-46342 | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-c |
No comments yet