CVE-2024-34344Disclosure(nuxt / nuxt)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them to execute arbitrary commands. Users who open a malicious web page in the browser while running the test locally are affected by this vulnerability, which results in the remote code execution from the malicious web page. Since web pages can send requests to arbitrary addresses, a malicious web page can repeatedly try to exploit this vulnerability, which then triggers the exploit when the test server starts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nuxt

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
nuxt

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Technical Details · 2026-03-12: 203-12
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    General

    🔴 https://dailycve.com/nuxt-uri-scheme-bypass-#cve-2024-34344-critical/ OneUptime, Improper Authorization, CVE-2026-30959 (Medium)

    Post summary

    The text references two CVEs, describing their severity and type but does not provide additional details such as PoC, exploitation, patch, or false positive information.

    0000050
    167 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 https://dailycve.com/oneuptime-remote-code-execution-#cve-2026-30921-critical-2/ Nuxt, URI Scheme Bypass, CVE-2024-34344 (Critical)

    Post summary

    The post highlights newly disclosed critical vulnerabilities: CVE‑2026‑30921 (remote code execution in OneUptime) and CVE‑2024‑34344 (URI scheme bypass).

    0000048
    168 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnuxtnuxt---

Explore more