Overview
Canonical component data stored by Polaris.
4.4.6
npm
library
1
58
pkg:npm/[email protected]
Maintenance
Derived from available component and registry data
High
80 days
Current
Yes
Lifecycle
Source: endoflife.date
4
—
—
No
4.5.2
Registry
Source: deps.dev
npm
3.21.11
5/18/2026
36
11
Known Vulnerabilities
Source: OSV.dev
GHSA-48hr-524c-v5w3
Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-534h-c3cw-v3h9
Nuxt dev server vite-node IPC socket is world-connectable on Linux
GHSA-934w-87qh-qr26
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
GHSA-9473-5f9j-94wq
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9pgf-384g-p7mv
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-c9cv-mq2m-ppp3
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
GHSA-hxcr-hm88-mpq6
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
GHSA-m3q2-p4fw-w38m
Cross-site scripting via <NoScript> slot content in Nuxt's head components
GHSA-mm7m-92g8-7m47
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
GHSA-rq7w-g337-39qq
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
GHSA-wm8w-6qjm-cv43
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
Security
Source: OpenSSF Scorecard
Systems (1)
Dependencies
58 direct dependencies