Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 28 SEP 2026

Nuxt · AUTOMATIC DISCOVERY

Nuxt 3

Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductNuxt
Release3
End of Support31 July 2026
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 1 Oct 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2026-71321High severity

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

pkg:npm/nuxtFixed: 4.5.1, 3.21.10

OSV record
CVE-2026-71320High severity

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

pkg:npm/nuxtFixed: 4.5.1, 3.21.10

OSV record
CVE-2026-56301Medium severity

Nuxt dev server vite-node IPC socket is world-connectable on Linux

pkg:npm/nuxtFixed: 4.4.7, 3.21.7

OSV record
CVE-2026-56326Medium severity

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

pkg:npm/nuxtFixed: 4.4.7, 3.21.7

OSV record
CVE-2026-53722Medium severity

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

pkg:npm/nuxtFixed: 4.4.7, 3.21.7

OSV record
CVE-2026-72744Medium severity

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

pkg:npm/nuxtFixed: 4.5.1, 3.21.10

OSV record
CVE-2026-71318Medium severity

Nuxt: Unauthorized Component Instantiation via Server Island Props

pkg:npm/nuxtFixed: 4.5.1, 3.21.10

OSV record
CVE-2026-56317Low severity

Cross-site scripting via <NoScript> slot content in Nuxt's head components

pkg:npm/nuxtFixed: 4.4.7, 3.21.7

OSV record

Source evidence

PRIMARYManual

Nuxt official lifecycle source

Release | | Initial release | End Of Life | Docs | 3.x (unsupported) | | 2022-11-16 | 2026-07-31 | nuxt.com

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 28 Sep 2026 · Review state accepted

Open official vendor source