CVE-2025-59414: Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
(updated )
A client-side path traversal vulnerability in Nuxt’s Island payload revival mechanism allowed attackers to manipulate client-side requests to different endpoints within the same application domain when specific prerendering conditions are met.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-59414 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →