Nuxt is a free and open-source framework with an intuitive and extendable way to create type-safe, performant and production-grade full-stack web applications and websites with Vue.js.
88%
Total Score
100
17
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-72744 nuxt is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 4.4.7 - 4.5.1 and 3.21.7 - 3.21.10. | 3.21.7 - 3.21.104.4.7 - 4.5.1 | Medium |
CVE-2026-71321 nuxt is vulnerable to Inefficient Algorithmic Complexity in versions 4.0.0 - 4.5.1 and 3.1.0 - 3.21.10. | 3.1.0 - 3.21.104.0.0 - 4.5.1 | High |
CVE-2026-71320 nuxt is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 4.0.0 - 4.5.1 and 3.4.0 - 3.21.10. | 3.4.0 - 3.21.104.0.0 - 4.5.1 | High |
CVE-2026-71318 nuxt is vulnerable to Improper Input Validation in versions 4.0.0 - 4.5.1 and 3.1.0 - 3.21.10. | 3.1.0 - 3.21.104.0.0 - 4.5.1 | Medium |
CVE-2026-71316 nuxt is vulnerable to Use of Cache Containing Sensitive Information in versions 4.4.0 - 4.5.0. | 4.4.0 - 4.5.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
ufo Version ^1.6.4 | — | — |
vue Version ^3.5.40 | — | — |
defu Version ^6.1.7 | — | — |
errx Version ^0.1.2 | — | — |
jiti Version ^2.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant