VYPR
High severity8.2NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026

CVE-2026-53721

CVE-2026-53721

Description

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nuxtnpm
>= 4.0.0, < 4.4.74.4.7
nuxtnpm
>= 3.11.0, < 3.21.73.21.7

Affected products

3
  • Nuxt/Nuxtreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: >=3.11.0 <3.21.7, >=4.0.0 <4.4.7
  • ghsa-coords
    Range: >= 4.0.0, < 4.4.7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.