StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
HIGHSupply chain

CVE-2026-53721

npm · nuxt

Summary

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

References

  • https://github.com/nuxt/nuxt/security/advisories/GHSA-mm7m-92g8-7m47
  • https://nvd.nist.gov/vuln/detail/CVE-2026-53721
  • https://github.com/nuxt/nuxt/commit/07e39cd6f26e407b4192b7865bd17bc44536b9bb
SourceStateward
Severityhigh
EPSS0.3% (p21)
Also known asGHSA-mm7m-92g8-7m47
Added2026-06-16

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • HIGHCVE-2026-52801

    Gogs has the ability to import local repositories via Mirror Settings

  • HIGHCVE-2026-52800

    Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

  • HIGHCVE-2026-52799

    Gogs Missing Authorization in Attachment Download

  • HIGHCVE-2026-52798

    Gogs has Stored XSS in `.ipynb` Preview

  • MEDIUMCVE-2026-50179

    @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

  • HIGHCVE-2026-54353

    @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture