chore(deps): update dependency nuxt to v3.21.7 [security] - #231
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency nuxt to v3.21.7 [security]#231renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
3 times, most recently
from
March 17, 2025 14:11
1ab3483 to
b2501f7
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
April 1, 2025 08:23
b2501f7 to
57729a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
April 8, 2025 15:51
57729a8 to
fb7208b
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
April 24, 2025 13:04
fb7208b to
6c23c8d
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
May 19, 2025 15:28
6c23c8d to
0dcf426
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
June 4, 2025 07:22
cbd2a8e to
5dbed3b
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
June 22, 2025 12:02
5dbed3b to
10a5008
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
July 2, 2025 20:05
10a5008 to
d335ab2
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
August 13, 2025 12:47
72addf9 to
1b9a047
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
August 19, 2025 11:59
1b9a047 to
978e89a
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
August 31, 2025 12:06
978e89a to
f630878
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
September 25, 2025 17:42
f630878 to
19c4266
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
October 15, 2025 22:51
19c4266 to
11c7539
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
October 21, 2025 19:35
11c7539 to
b1847cb
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
November 10, 2025 22:59
b1847cb to
dfe4e0e
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
November 18, 2025 23:09
dfe4e0e to
96200a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
December 3, 2025 16:38
96200a8 to
c4391c1
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
December 31, 2025 18:44
c4391c1 to
b1cf454
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
January 8, 2026 21:03
b1cf454 to
588398b
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
January 23, 2026 21:15
427abdf to
5e832b4
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
February 2, 2026 15:48
5e832b4 to
9698d9c
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
February 17, 2026 18:34
4171025 to
81bcf42
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
3 times, most recently
from
April 1, 2026 21:52
4ded004 to
b460fa5
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
April 8, 2026 15:57
b460fa5 to
f5688fb
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
April 27, 2026 20:09
f5688fb to
8a7b481
Compare
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
April 29, 2026 17:43
8a7b481 to
5da17e0
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
May 12, 2026 14:26
5da17e0 to
642667f
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
May 18, 2026 13:58
642667f to
c840190
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
June 2, 2026 00:12
a6db30d to
fd3d833
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
June 11, 2026 10:06
fd3d833 to
7b44e35
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
July 17, 2026 03:20
a84e222 to
4c1abc4
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
July 24, 2026 22:52
d471d0e to
82a42c3
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
July 30, 2026 19:52
82a42c3 to
42c2a1e
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
2 times, most recently
from
August 14, 2026 22:00
74dff48 to
a3d7d79
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-vulnerability
branch
from
August 26, 2026 10:46
a3d7d79 to
b9ce56c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.0→3.21.7nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
CVE-2024-34343 / GHSA-vf6r-87q4-2vjf
More information
Details
Summary
The
navigateTofunction attempts to blockthejavascript:protocol, but does not correctly use API's provided byunjs/ufo. This library also contains parsing discrepancies.Details
The function first tests to see if the specified URL has a protocol. This uses the unjs/ufo package for URL parsing. This function works effectively, and returns true for a
javascript:protocol.After this, the URL is parsed using the
parseURLfunction. This function will refuse to parse poorly formatted URLs. Parsingjavascript:alert(1)returns null/"" for all values.Next, the protocol of the URL is then checked using the
isScriptProtocolfunction. This function simply checks the input against a list of protocols, and does not perform any parsing.The combination of refusing to parse poorly formatted URLs, and not performing additional parsing means that script checks fail as no protocol can be found. Even if a protocol was identified, whitespace is not stripped in the
parseURLimplementation, bypassing theisScriptProtocolchecks.Certain special protocols are identified at the top of
parseURL. Inserting a newline or tab into this sequence will block the special protocol check, and bypass the latter checks.PoC
POC - https://stackblitz.com/edit/nuxt-xss-navigateto?file=app.vue
Attempt payload X, then attempt payload Y.
Impact
XSS, access to cookies, make requests on user's behalf.
Recommendations
As always with these bugs, the
URLconstructor provided by the browser is always the safest method of parsing a URL.Given the cross-platform requirements of nuxt/ufo a more appropriate solution is to make parsing consistent between functions, and to adapt parsing to be more consistent with the WHATWG URL specification.
Note
I've reported this vulnerability here as it is unclear if this is a bug in ufo or a misuse of the ufo library.
This ONLY has impact after SSR has occurred, the
javascript:protocol within a location header does not trigger XSS.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Nuxt allows DOS via cache poisoning with payload rendering response
CVE-2025-27415 / GHSA-jvhm-gjrh-3h93
More information
Details
Summary
By sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of a site.
It is possible to craft a request, such as
https://mysite.com/?/_payload.jsonwhich will be rendered as JSON. If the CDN in front of a Nuxt site ignores the query string when determining whether to cache a route, then this JSON response could be served to future visitors to the site.Impact
An attacker can perform this attack to a vulnerable site in order to make a site unavailable indefinitely. It is also possible in the case where the cache will be reset to make a small script to send a request each X seconds (=caching duration) so that the cache is permanently poisoned making the site completely unavailable.
Conclusion :
This is similar to a vulnerability in Next.js that resulted in CVE-2024-46982 (and see this article, in particular the "Internal URL parameter and pageProps" part, the latter being very similar to the one concerning us here.)
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Cross-site scripting via slot content in Nuxt's head components
GHSA-m3q2-p4fw-w38m
More information
Details
Impact
Nuxt's globally registered
<NoScript>component (from@unhead/vuehead components, re-exported by Nuxt) wrote its default-slot content to theinnerHTMLof the<noscript>head tag, bypassing the HTML escaping that{{ }}interpolation normally applies in Vue templates.Applications that placed untrusted, attacker-controllable data inside a
<NoScript>slot, for example:would emit that value unescaped inside
<noscript>in the server-rendered HTML. With scripting enabled, the HTML parser treats<noscript>content in<head>under the "in head noscript" insertion mode: any tag other thanlink,meta,noframes, orstyleimplicitly closes<noscript>and is re-processed in the head. A payload such as<script>...</script>therefore escapes the element and executes in the document context.Sibling head components (
<Style>,<Title>) were not affected because they already routed slot text through the safetextContentpath.Affected versions
All currently supported versions of
nuxtthat ship the<NoScript>global component.Patches
Fixed in
nuxt@4.4.7(commit4b054e9d) and backported tonuxt@3.21.7(commit7fea9fd6). The fix escapes<NoScript>slot content withescapeHtmlfrom@vue/sharedand writes it totextContentrather thaninnerHTML. Slot content is now rendered as text; intentional markup inside<NoScript>is no longer parsed as HTML.Workarounds
Until you can upgrade:
<NoScript>slots. Replace<NoScript>{{ x }}</NoScript>with a static string, or sanitise / HTML-escapexat the source.useHead({ noscript: [{ textContent: escapedValue }] })after escapingescapedValue.Credit
Reported to Anthropic's coordinated vulnerability disclosure pipeline by Claude (Anthropic's AI assistant) and triaged by the Anthropic security team. Reference: ANT-2026-4NJYDFFM.
Independently reported by @alcls01111 via GitHub's coordinated disclosure flow (
GHSA-8grp-wcq9-925q), closed as a duplicate of this advisory.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Nuxt: Reflected XSS in
<NuxtLink>via unsanitisedjavascript:ordata:URLCVE-2026-53722 / GHSA-934w-87qh-qr26
More information
Details
Summary
<NuxtLink>did not validate the URL scheme of values bound to itstoorhrefprops before rendering them into thehrefattribute of the underlying<a>element. When an application binds attacker-controlled input (a query parameter, a CMS field, a user-supplied profile URL) to<NuxtLink :to>or:href, the attacker can supply ajavascript:orvbscript:URL that is reflected verbatim into the rendered markup. Clicking the link executes the supplied script in the origin of the Nuxt application, resulting in reflected DOM-based cross-site scripting. Adata:text/html,...payload reflected through the same sink does not execute in the application's origin but enables a same-tab phishing surface anchored to a legitimate application link.The same value was exposed to consumers of the component's
customslot via thehrefandroute.hrefprops, so applications that re-bind those values to their own anchors were affected identically.Unlike the previously reported
navigateToissue (CVE-2024-34343), the sink here is the rendered anchor itself; the existingisScriptProtocolchecks innavigateToandreloadNuxtAppare not on the code path. TheonClickhandler intentionally returns early for external links so the browser's native protocol-based navigation runs.Affected component
packages/nuxt/src/app/components/nuxt-link.tsh('a', { href: href.value, ... })in the default render, plus thehref/route.hrefprops passed to thecustomslot.hasProtocol(path, { acceptRelative: true })value as an "external link", then rendered the value directly as<a href>without rejecting script-capable protocols. There was no equivalent of thenavigateToisScriptProtocol(protocol)gate in this path.Impact
Any Nuxt application that binds user-controlled values to
<NuxtLink :to>/:hrefwas vulnerable. Common shapes: profile-link rendering (<NuxtLink :to="user.website">), "share this" / "open in new tab" handlers that pass through a query parameter, CMS-driven landing pages that render<NuxtLink :to="cms.cta.url">, and marketplace listings that show seller-supplied links.For
javascript:/vbscript:the primitive is reflected XSS in the application's first-party origin (session theft for non-HttpOnlycookies, CSRF token theft, account takeover via DOM rewriting, credential harvesting via fake login overlays). Fordata:text/html,...the attacker gets a same-tab phishing surface anchored to a legitimate application link.Patches
Fixed in
nuxt@4.4.7(commit0103ce06) and backported tonuxt@3.21.7(commit53284043). The fix sanitises the resolved externalhrefbefore it is passed to<a>or thecustomslot: control characters and whitespace are stripped, leadingview-source:prefixes are unwrapped, and any remaining script-capable scheme (perisScriptProtocol) causes thehrefto be replaced with an empty string.Workarounds
Until you can upgrade, validate URLs at the source before binding them to
<NuxtLink :to>/:href. For example, only accept paths that start with/(and not//), or run user-supplied URLs throughnew URL(value)and reject anything whoseprotocolis not in an allow-list (typicallyhttp:andhttps:).Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nuxt/nuxt (nuxt)
v3.21.7Compare Source
👉 make sure to check https://github.com/nuxt/nuxt/security/advisories to view open advisories resolved by this release.
👉 Changelog
compare changes
🩹 Fixes
noSSRbefore deciding payload extraction (#35108)allowDirs(#35112)pathefor buildCache path boundary check (#35111)isValidin dev clipboard-copy listener (#35109)reloadNuxtApppath before reload (#35115)clientServerwithssr: false(#34959).d.mts/.d.ctsinresolveTypePaths(#35235)<NuxtClientFallback>ssr output (#35199)isScriptProtocolguard tonavigateToopen option (#35206)defuin app config template (40bedf0db)vue-router(3f3e3fa7b)<NoScript>slot content (7fea9fd68)navigateTo(1f2dd5e78)reloadNuxtApp(6497d99dd)<NuxtLink>href (53284043d)defu(d11d7b1b5)📖 Documentation
🏡 Chore
execFileSyncfor safety in release scripts (9a455a658)✅ Tests
🤖 CI
❤️ Contributors
v3.21.6Compare Source
👉 Changelog
compare changes
🩹 Fixes
setPageLayoutprops on same-path navigation (#35055)useLoadingIndicatorproperties as readonly (#35062)statusCodefor nitro v2 compatibility (82dcd6a31)💅 Refactors
📖 Documentation
🏡 Chore
✅ Tests
app/(6d2ac69ff)🤖 CI
test:enginesfails (958abb882)❤️ Contributors
v3.21.5Compare Source
👉 Changelog
compare changes
🔥 Performance
isIgnoredrelative (#35015)🩹 Fixes
/+ overridessr: true(#34990).envbefore resolving nuxt schema (#34958)serverHandlersarray afternitro:config(#34985)📖 Documentation
🏡 Chore
✅ Tests
buildDirper matrix project for shared fixtures (#35007)❤️ Contributors
v3.21.4Compare Source
v3.21.2Compare Source
v3.21.1Compare Source
👉 Changelog
compare changes
🩹 Fixes
server/forbuilder:watchhook (#34208)x-nitro-prerenderheader (#34202)error.messagefor fatal errors (#34226)#appbarrel export in keyed functions (#34199)datetime in` (#33992)nuxt/schema(#34255)meta.name(#34263)#componentsimport mapping conflict for packages outside rootDir (#34139)nuxt/schemaonce more (9f5bb611d)💅 Refactors
genObjectKeyto omit unnecessary quotes (#34245)ComponentPropshelper to extract layout props (#34248)📖 Documentation
keyedComposables(#34201)🏡 Chore
pxfromwidthattribute (e80147f7d)✅ Tests
<NuxtPage>navigation (707a9dc44)❤️ Contributors
v3.21.0Compare Source
Nuxt 4.3 and 3.21 bring powerful new features for layouts, caching, and developer experience – plus significant performance improvements under the hood.
📣 Some News
Extended v3 Support
Early this month, I opened a discussion to find out how the upgrade had gone from v3 to v4. I was really pleased to hear how well it had gone for most people.
Having said that, we're committed to making sure no one gets left behind. And so we will continue to provide security updates and critical bug fix releases beyond the previously announced end-of-life date of January 31, 2026, meaning Nuxt v3 will meet its end-of-life on July 31, 2026.
Preparing for Nuxt 5
We're closer than ever to the releases of Nuxt v5 and Nitro v3. In the coming weeks, the
mainbranch of the Nuxt repository will begin receiving initial commits for Nuxt 5. However, it's still business as usual.mainbranch4.xand3.xbranchesKeep an eye out on the Upgrade Guide – we'll be adding details about how you can already start migrating your projects to prepare for Nuxt v4 with
future.compatibilityVersion: 5.🗂️ Route Rule Layouts
But that's enough about the future. We have a lot of good things for you today!
First, you can now set layouts directly in route rules using the new
appLayoutproperty (#31092). This provides a centralized, declarative way to manage layouts across your application without scatteringdefinePageMetacalls throughout your pages.This might be useful for:
📦 ISR/SWR Payload Extraction
Payload extraction now works with ISR (incremental static regeneration), SWR (stale-while-revalidate) and cache
routeRules(#33467). Previously, only pre-rendered pages could generate_payload.jsonfiles.This means:
🧹 Dev Mode Payload Extraction
Related to the above, payload extraction now also works in development mode (#30784). This makes it easier to test and debug payload behavior without needing to run a production build.
🚫 Disable Modules from Layers
When extending Nuxt layers, you can now disable specific modules that you don't need (#33883). Just pass
falseto the module's options:🏷️ Route Groups in Page Meta
Route groups (folders wrapped in parentheses like
(protected)/) are now exposed in page meta (#33460). This makes it easy to check which groups a route belongs to in middleware or anywhere you have access to the route.This provides a clean, convention-based approach to route-level authorization without needing to add
definePageMetato every protected page.🎨 Layout Props with
setPageLayoutThe
setPageLayoutcomposable now accepts a second parameter to pass props to your layout (#33805):🔧
#serverAliasA new
#serveralias provides clean imports within your server directory (#33870), similar to how#sharedworks:The alias includes import protection – you can't accidentally import
#servercode from client or shared contexts.🪟 Draggable Error Overlay
The development error overlay introduced in Nuxt 4.2 is now draggable and can be minimized (#33695). You can:
This is a quality-of-life improvement when you're iterating on fixes and don't want the overlay blocking your view.
https://github.com/user-attachments/assets/nuxt_4-3_error_demo.mp4
⚙️ Async Plugin Constructors
Module authors can now use async functions when adding build plugins (#33619):
This enables true lazy loading of build plugins, avoiding unnecessary code loading when plugins aren't needed.
🚀 Performance Improvements
This release includes several performance optimizations for faster builds:
nuxt:ssr-stylesplugin is now significantly faster (#33862, #33865)rou3, removing the need forradix3in the client bundle and eliminating app manifest fetches (#33920)🎨 Inline Styles for Webpack/Rspack
The
inlineStylesfeature now works with webpack and rspack builders (#33966), not just Vite. This enables critical CSS inlining for better Core Web Vitals regardless of your bundler choice.statusCode→status,statusMessage→statusTextIn preparation for Nitro v3 and H3 v2, we're moving to use Web API naming conventions (#33912). The old properties still work but are deprecated in advance of v5:
🐛 Bug Fixes
Notable fixes in this release:
keyattribute (#33958, #33963)useCookieunsafe number parsing during decode (#34007)NuxtPagenot re-rendering when nestedNuxtLayouthas layouts disabled (#34078)allowArbitraryExtensionsby default in TypeScript config (#34084)noUncheckedIndexedAccessto server tsconfig for safer typing (#33985)📚 Documentation
🎉 Nuxt 3.21.0
Alongside v4.3.0, we're releasing Nuxt v3.21.0 with many of the same improvements backported to the 3.x branch. This release includes:
setPageLayout,#serveralias, draggable error overlay, and morefalseuseCookienumber parsing, head component deduplication, and more✅ Upgrading
Our recommendation for upgrading is to run:
This will deduplicate your lockfile and help ensure you pull in updates from other dependencies that Nuxt relies on, particularly in the unjs ecosystem.
👉 Changelog
compare changes
🚀 Enhancements
#serveralias for server directory imports (#33870)crosswstypes (6ff79ea6c)false(#33883)moduleDependenciesas an async function (#33504)appLayoutin route rules (#31092)setPageLayout(#33805)🔥 Performance
nuxt:ssr-stylesplugin (#33862)🩹 Fixes
router.replacein page hmr (#33897)page:loading:endin cache if already called (fbbe10133)NUXT_VITE_NODE_OPTIONS(8abb7ef5b)appMiddlewarereferences invalid key (ed8bb68c5)nuxt/meta(b748840bc)keyfor tag deduplication in<Head>component (#33958)build.transpilewhen initialising vite (#33868)onUpgradearguments with types (#33988)rou3(7da94e8c3)noUncheckedIndexedAccessto server tsconfig (#33985)useRequestFetch(#33976)h3types to auto-imports (#34035)nuxt/schema(9b40196a6)NuxtPagewhen nestedNuxtLayouthas explicitly disabled layouts (#34078)allowArbitraryExtensionsby default (#34084)useAsyncDatadebounced execute post watcher flush (#34125)typeFromsupport forimports.d.tstemplate exports (#34135)hydrate-nevercomponents (#34132)?
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.