Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 27 SEP 2026

Vuejs · AUTOMATIC DISCOVERY

Vue Lifecycle policy

Vue is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

Vue is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductVue
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 29 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2024-9506Low severity

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

pkg:npm/vueFixed: 3.0.0-alpha.0

OSV record

Source evidence

PRIMARYManual

Vue official lifecycle source

You can install the latest pre-releases from npm using npx install-vue@alpha , npx install-vue@beta , or npx install-vue@rc . For testing changes not yet included in tagged pre-releases, every commit to the vuejs/core repository is published as a temporary continuous-release preview, which you can install using npx install-vue@edge . | Pre-releases are meant for integration / stability testing, and for early adopters to provide feedback for unstable features. Do not use pre-releases in production. All pre-releases are considered unstable and may ship breaking changes in between, so always pin to exact versions when using pre-releases. | Deprecations ​ | We may periodically deprecate features that have new, better replacements in minor releases. Deprecated features will continue to work, and will be removed in the next major release after it entered deprecated status. | RFCs ​ | New features with substantial API surface and major changes to Vue will go through the Request for Comments (RFC) process. The RFC process is intended to provide a consistent and controlled path for new features to enter the framework, and give the users an opportunity to participate and offer feedback in the design process. | The RFC process is conducted in the vuejs/rfcs repo on GitHub.

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 27 Sep 2026 · Review state accepted

Open official vendor source