The Nuxt team has disclosed four security vulnerabilities. Here’s what Netlify customers need to know. Vulnerabilities CVE-2026-47200 : Route middleware bypass via island page endpoints (nuxt 3.11.0–3.21.5, 4.0.0-alpha.1–4.4.5) CVE-2026-46342 : Island response not validated against request props (nuxt 3.1.0–3.21.5, 4.0.0-alpha.1–4.4.5) CVE-2026-45670 : Dev server exposes built source over LAN (nuxt 3.15.4–3.21.5, 4.0.0-alpha.1–4.4.5) CVE-2026-45669 : Reflected XSS via navigateTo with external: true (nuxt 3.4.3–3.21.5, 4.0.0-alpha.1–4.4.5) Impact on Netlify CVE-2026-47200 (route middleware bypa
Security update: multiple vulnerabilities in Nuxt
calendar_today
May 19, 2026
domain
netlify