{"id":"CVE-2023-3224","aliases":["GHSA-gc34-5v43-h7v8"],"url":"https://o3.security/vulnerability/CVE-2023-3224","summary":"Code Injection in nuxt/nuxt","details":"he Nuxt dev server between versions 3.4.0 and 3.4.3 is vulnerable to code injection when it is exposed publicly.","published":"2023-06-13T00:00:00Z","modified":"2026-08-12T03:51:20.592568605Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"nuxt","fixedVersion":"3.4.3"}],"fix":{"url":"https://github.com/nuxt/nuxt/commit/65a8f4eb3ef1b249a95fd59e323835a96428baff","label":"nuxt/nuxt@65a8f4e"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/1eb74fd8-0258-4c1f-a904-83b52e373a87"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3224.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3224"},{"type":"FIX","url":"https://github.com/nuxt/nuxt/commit/65a8f4eb3ef1b249a95fd59e323835a96428baff"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/issues/21694"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/72ba53efbc2384f802d654fffd92eaf36a81b507"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commits/v3.4.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.592568605Z"}}