Vulnerabilities/

Nuxt vulnerable to remote code execution via the browser when running the test locally

Severity:
High

Description

Due to the insufficient validation of the path parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them to execute arbitrary commands.

Recommendation

Update the nuxt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nuxt
Anything's wrong? Let us know Last updated on November 18, 2024

This issue is available in SmartScanner Professional

See Pricing