Intel

AIKIDO-2025-10055

@nuxt/content is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

51

Medium Risk

This Affects:

JS@nuxt/content
3.0.0 - 3.0.0
Fixed in 3.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a design flaw when handling SQL queries that involve user inputs before proper validation. While frontend frameworks generally offer robust protection against injection attacks, this vulnerability can lead to unauthorized access to data, data corruption, or even a compromise of the database. This risk arises from the failure to validate the query before execution, which undermines the overall security.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@nuxt/content is vulnerable to Improper Input Validation in versions 3.0.0 - 3.0.0.

How to fix this

Upgrade the @nuxt/content library to the patch version.