Nuxt is a free and open-source framework with an intuitive and extendable way to create type-safe, performant and production-grade full-stack web applications and websites with Vue.js.
90%
Total Score
62
90
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10948 New nuxt is vulnerable to Authentication Bypass in versions 3.11.0 - 3.21.5 and 4.0.0 - 4.4.5. | 3.11.0 - 3.21.54.0.0 - 4.4.5 | Medium |
CVE-2026-46342 nuxt is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.1.0 - 3.21.5 and 4.0.0-alpha.1 - 4.4.5. | 3.1.0 - 3.21.54.0.0-alpha.1 - 4.4.5 | Low |
CVE-2026-45669 nuxt is vulnerable to Improper Neutralization of Script in Attributes in a Web Page in versions 3.4.3 - 3.21.5 and 4.0.0-alpha.1 - 4.4.5. | 3.4.3 - 3.21.54.0.0-alpha.1 - 4.4.5 | Medium |
CVE-2025-59414 nuxt is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 3.6.0 - 3.19.0 and 4.0.0 - 4.1.0. | 3.6.0 - 3.19.04.0.0 - 4.1.0 | Low |
CVE-2025-27415 nuxt is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data in versions 3.0.0 - 3.16.0. | 3.0.0 - 3.16.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
ufo Version ^1.6.4 | — | — |
vue Version ^3.5.34 | — | — |
defu Version ^6.1.7 | — | — |
errx Version ^0.1.0 | — | — |
jiti Version ^2.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant