{{ message }}
Security: nuxt/ui
Security
SECURITY.md
To report a vulnerability, please privately report it via the Security tab on the correct GitHub repository (see documentation). If that is impossible, feel free to send an email to security@nuxtjs.org instead.
All security vulnerabilities will be promptly verified and addressed.
While the discovery of new vulnerabilities is rare, we also recommend always using the latest versions of Nuxt and other dependencies by maintaining lock files (yarn.lock, package-lock.json and pnpm-lock.yaml) in order to ensure your application remains as secure as possible.
-
UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydrationGHSA-gj2h-2fpw-fhv9 published
May 29, 2026 by benjamincanacModerate -
Cross-site scripting in Nuxt AI Chatbot Template (chat-template.nuxt.dev) via unsanitized chat inputGHSA-wpmj-r844-vvfg published
Jan 12, 2026 by benjamincanacCritical
Learn more about advisories related to nuxt/ui in the GitHub Advisory Database