Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYFRAMEWORKVERIFIED

Nuxt

Nuxt

Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Nuxt is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

Lifecycle records

ReleaseBoundaryDate
1Support ends21 September 2019
2Support ends30 June 2024
3Support ends31 July 2026

Official sources

VERIFIED

Nuxt official lifecycle source

Checked automatically.

Extracted 3 lifecycle record(s), including 3 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

Fixed: 4.5.1, 3.21.10

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Fixed: 4.5.1, 3.21.10

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

Fixed: 4.5.1

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Fixed: 4.4.7, 3.21.7

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Fixed: 4.4.7, 3.21.7

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Fixed: 4.5.1, 3.21.10

Nuxt: Unauthorized Component Instantiation via Server Island Props

Fixed: 4.5.1, 3.21.10

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Fixed: 4.4.7, 3.21.7