Nuxt · AUTOMATIC DISCOVERY
Nuxt 3
Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Product overview
Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Application development components
- Versioned runtime or build interfaces
- Security and compatibility maintenance
Typical use
Used by software teams to build, run or maintain applications.
Deployment
Included in source projects, application dependencies, build systems or managed runtimes.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
Collected lifecycle data
| Product | Nuxt |
|---|---|
| Release | 3 |
| End of Support | 31 July 2026 |
| Date precision | Day |
Known exploited vulnerabilities
Catalogue updated 1 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
No CISA known-exploited entries currently match this mapped product family.
This does not mean the product has no vulnerabilities.
Package vulnerability advisories
Checked 1 Oct 2026OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
OSV recordNuxt dev server vite-node IPC socket is world-connectable on Linux
OSV recordNuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
OSV recordNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
OSV recordNuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
OSV recordNuxt: Unauthorized Component Instantiation via Server Island Props
OSV recordCross-site scripting via <NoScript> slot content in Nuxt's head components
OSV recordSource evidence
Nuxt official lifecycle source
Release | | Initial release | End Of Life | Docs | 3.x (unsupported) | | 2022-11-16 | 2026-07-31 | nuxt.com
Publisher identity used by product-specific official-source collectors.
Open official vendor source