Overview
Canonical component data stored by Polaris.
4.3.1
npm
library
1
59
pkg:npm/[email protected]
Maintenance
Derived from available component and registry data
High
180 days
Current
Yes
Lifecycle
Source: endoflife.date
4
—
—
No
4.5.2
Registry
Source: deps.dev
npm
3.21.11
2/7/2026
36
13
Known Vulnerabilities
Source: OSV.dev
GHSA-48hr-524c-v5w3
Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-534h-c3cw-v3h9
Nuxt dev server vite-node IPC socket is world-connectable on Linux
GHSA-934w-87qh-qr26
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
GHSA-9473-5f9j-94wq
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9pgf-384g-p7mv
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-c9cv-mq2m-ppp3
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
GHSA-fx6j-w5w5-h468
Nuxt: Reflected XSS in `navigateTo()` external redirect
GHSA-g8wj-3cr3-6w7v
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
GHSA-hg3f-28rg-4jxj
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
GHSA-hxcr-hm88-mpq6
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
GHSA-m3q2-p4fw-w38m
Cross-site scripting via <NoScript> slot content in Nuxt's head components
GHSA-mm7m-92g8-7m47
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
GHSA-rq7w-g337-39qq
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Security
Source: OpenSSF Scorecard
Systems (1)
Dependencies
59 direct dependencies