Nuxt is a Vue.js framework and meta-framework for building web applications, distributed across a concentrated product portfolio that includes the core framework, tooling such as devtools and og_image generation, and related ecosystem components. Despite its narrow vendor footprint, the framework occupies a prominent position in the modern JavaScript development landscape due to widespread adoption in production applications. The vulnerability exposure concentrates on application-layer and code-generation concerns: cross-site scripting and input-neutralization flaws, code injection through improper generation controls, path traversal in file-handling routines, and acceptance of extraneous untrusted data mixed with trusted inputs—weakness classes that reflect the framework's role in bridging client and server rendering, templating, and dynamic code execution. Defenders tracking applications built on this framework should prioritize updates to the core framework and development tooling, since flaws in the build or rendering layer can propagate broadly to dependent projects. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuxt over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3224CRITICAL Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. | Jun 13, 2023 | 9.8 | 63 | NO | NO |
CVE-2026-53721HIGH Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensi | Jun 12, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-56317MEDIUM Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. | Jun 20, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-56326MEDIUM Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like | Jun 22, 2026 | 6.1 | 27 | NO | NO |
CVE-2026-34404HIGH Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contai | Mar 31, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-56301MEDIUM Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket witho | Jun 23, 2026 | 5.5 | 25 | NO | NO |
CVE-2026-56698MEDIUM Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supp | Jun 22, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-56697MEDIUM Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but res | Jun 22, 2026 | 6.1 | 25 | NO | NO |
CVE-2024-34344HIGH Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestC | Aug 5, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-23657HIGH Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC fu | Aug 5, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuxt.
Media articles that mention a CVE ID that affects a product developed by Nuxt — matched by CVE ID, not by vendor name.