Skip to content

[GHSA-4jjw-pwvw-q6w3] Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3... - #9086

Open
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9086from
antonisloukis-GHSA-4jjw-pwvw-q6w3
Open

[GHSA-4jjw-pwvw-q6w3] Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3...#9086
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9086from
antonisloukis-GHSA-4jjw-pwvw-q6w3

Conversation

@antonisloukis

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Source code location
  • Summary

Comments
This advisory is missing the affected npm package/version metadata and source code location.

The official Nuxt security advisory GHSA-7c4v-fwgw-9rf7 identifies the affected package as nuxt on npm and documents two affected release lines:

  • = 4.4.7, < 4.5.1 — patched in 4.5.1

  • = 3.21.7, < 3.21.10 — patched in 3.21.10

Added:

  • Ecosystem: npm
  • Package: nuxt
  • Affected version ranges for both the Nuxt 4.x and 3.x release lines
  • Patched versions: 4.5.1 and 3.21.10
  • Source repository: https://github.com/nuxt/nuxt

The title was also aligned with the upstream Nuxt security advisory.

Upstream advisory:
GHSA-7c4v-fwgw-9rf7

The CVSS v4 vector was normalized by omitting optional metrics set to X (Undefined); the base CVSS assessment was not changed.

@github-actions
github-actions Bot changed the base branch from main to antonisloukis/advisory-improvement-9086 August 12, 2026 09:24
@antonisloukis

Copy link
Copy Markdown
Author

Note: the advisory improvement form generated this PR with the existing CVSS v3 entry removed while normalizing the CVSS v4 vector.

My intended changes are the missing package/version metadata, source repository, summary, and CVSS v4 normalization. I did not intend to remove the existing CVSS v3 assessment, so please retain it if appropriate during curation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant