Medium severity6.1NVD Advisory· Published Jul 11, 2019· Updated Jun 17, 2026
CVE-2019-13506
CVE-2019-13506
Description
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@nuxt/devaluenpm | < 1.2.3 | 1.2.3 |
Affected products
3Patches
Vulnerability mechanics
References
9- github.com/nuxt/devalue/pull/8nvdPatchThird Party AdvisoryWEB
- github.com/nuxt/nuxt.js/commit/0d5dfe71917191c5b07f373896311f2d8f6b75benvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6677-83pp-f862ghsaADVISORY
- github.com/nuxt/devalue/releases/tag/v1.2.3nvdRelease NotesThird Party AdvisoryWEB
- github.com/nuxt/nuxt.js/compare/c0776eb...8d14cd4nvdRelease NotesThird Party AdvisoryWEB
- github.com/nuxt/nuxt.js/releases/tag/v2.6.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-13506ghsaADVISORY
- www.npmjs.com/advisories/814nvdThird Party AdvisoryWEB
- github.com/Rich-Harris/devalue/issues/19ghsaWEB
News mentions
0No linked articles in our index yet.