npmlibrarynuxt

Overview

Canonical component data stored by Polaris.

Version

4.4.8

Package Manager

npm

Type

library

Systems

2

Licenses
MIT
Direct Dependencies

73

Technology

nuxt

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:npm/[email protected]

Maintenance

Derived from available component and registry data

Healthy
Confidence

High

Version Age

59 days

Update Status

Current

Recent Activity

Yes

Reasons
Recent versionMature versionCurrent version

Lifecycle

Source: endoflife.date

Active
Matched Cycle

4

End of Life

Active Support Ends

LTS

No

Latest Version

4.5.2

Open endoflife.date

Registry

Source: deps.dev

Available
Ecosystem

npm

Latest Version

3.21.11

Published

6/8/2026

Recent Releases

36

Advisories

6

Open deps.dev

Known Vulnerabilities

Source: OSV.dev

6 found

GHSA-48hr-524c-v5w3

Nuxt: Unauthorized Component Instantiation via Server Island Props

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Versions
>= 4.0.0, before 4.5.1>= 3.1.0, before 3.21.10
Open advisory

GHSA-9473-5f9j-94wq

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
>= 4.0.0, before 4.5.1>= 3.4.0, before 3.21.10
Open advisory

GHSA-9pgf-384g-p7mv

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 4.0.0, before 4.5.1>= 3.1.0, before 3.21.10
Open advisory

GHSA-hxcr-hm88-mpq6

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 4.0.0, before 4.5.1>= 3.1.0, before 3.21.10
Open advisory

GHSA-hxvh-4h3w-prp9

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected Versions
>= 4.4.7, before 4.5.1>= 3.21.7, before 3.21.10
Open advisory

GHSA-wm8w-6qjm-cv43

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Versions
>= 4.4.0, before 4.5.1
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

73 direct dependencies

Global view