Nuxt is a JavaScript framework and associated utility libraries for building web applications, with a relatively narrow product portfolio spanning the core framework and auxiliary packages such as @nuxt/devalue and netlify-ipx. Observed vulnerabilities center on input-handling weaknesses characteristic of web frameworks, particularly cross-site scripting and server-side request forgery issues in page generation and request processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuxtjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39239MEDIUM netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially craf | Sep 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2019-13506MEDIUM @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS. | Jul 11, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuxtjs.
Media articles that mention a CVE ID that affects a product developed by Nuxtjs — matched by CVE ID, not by vendor name.