Update dependency nuxt to v3 #135
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: php. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
You have successfully remediated 80 vulnerabilities, but introduced 20 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-53892Path to dependency file: /src/Administration/Resources/app/administration/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/package.json Dependency Hierarchy: -> ❌ vue-i18n-9.2.2.tgz (Vulnerable Library) |
6.1 | Direct vue-i18n-9.2.2.tgz |
vue-i18n-9.2.2.tgz | https://github.com/intlify/vue-i18n.git - no_fix | None | ||
CVE-2025-54798Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> ❌ tmp-0.2.1.tgz (Vulnerable Library) |
2.5 | Transitive tmp-0.2.1.tgz |
cypress-3.1.2.tgz | Transitive 0.2.4 |
None | ||
CVE-2025-7783Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> ❌ form-data-2.3.3.tgz (Vulnerable Library) |
8.7 | Transitive form-data-2.3.3.tgz |
cypress-3.1.2.tgz | None | |||
CVE-2025-27415Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> ❌ nuxt-3.0.0.tgz (Vulnerable Library) |
7.5 | Direct nuxt-3.0.0.tgz |
nuxt-3.0.0.tgz | 3.16.0 | None | ||
CVE-2020-8203Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> vite-plugin-checker-0.5.6.tgz -> ❌ lodash.pick-4.4.0.tgz (Vulnerable Library) |
7.4 | Transitive lodash.pick-4.4.0.tgz |
nuxt-3.0.0.tgz | Transitive lodash - 4.17.19,lodash-es - 4.17.20 |
None | ||
CVE-2025-62522Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
6.5 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive https://gitlab.com/remram44/taguette.git - v1.5.0 |
None | ||
CVE-2025-32395Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
6.5 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive 4.5.13 |
None | ||
CVE-2025-24010Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
6.5 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive 4.5.6 |
None | ||
CVE-2023-28155Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> ❌ request-2.88.12.tgz (Vulnerable Library) |
6.1 | Transitive request-2.88.12.tgz |
cypress-3.1.2.tgz | Transitive 3.0.0 |
None | ||
WS-2023-0126Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> ❌ vite-builder-3.0.0.tgz (Vulnerable Library) |
5.3 | Transitive vite-builder-3.0.0.tgz |
nuxt-3.0.0.tgz | Transitive @nuxt/vite-builder - 3.4.2 |
None | ||
CVE-2025-58752Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
5.3 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive vite - 6.3.6,vite - 7.1.5,vite - 7.0.7,vite - 5.4.20 |
None | ||
CVE-2025-30208Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
5.3 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive 4.5.10 |
None | ||
CVE-2025-58751Path to dependency file: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Path to vulnerable library: /src/Administration/Resources/app/administration/build/nuxt-component-library/package.json Dependency Hierarchy: -> nuxt-3.0.0.tgz (Root Library) -> vite-builder-3.0.0.tgz -> ❌ vite-3.2.11.tgz (Vulnerable Library) |
4.3 | Transitive vite-3.2.11.tgz |
nuxt-3.0.0.tgz | Transitive 5.4.20 |
None | ||
CVE-2026-2391Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> ❌ qs-6.10.4.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.10.4.tgz |
cypress-3.1.2.tgz | Transitive 6.14.2 |
None | ||
CVE-2025-15284Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> ❌ qs-6.10.4.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.10.4.tgz |
cypress-3.1.2.tgz | Transitive qs - 6.14.1 |
None | ||
CVE-893166-217151Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> ❌ form-data-2.3.3.tgz (Vulnerable Library) |
9.8 | Transitive form-data-2.3.3.tgz |
cypress-3.1.2.tgz | None | |||
CVE-814504-1548Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> ❌ isstream-0.1.2.tgz (Vulnerable Library) |
9.8 | Transitive isstream-0.1.2.tgz |
cypress-3.1.2.tgz | None | |||
CVE-72435-185255Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> http-signature-1.3.6.tgz -> sshpk-1.17.0.tgz -> ❌ tweetnacl-0.14.5.tgz (Vulnerable Library) |
9.8 | Transitive tweetnacl-0.14.5.tgz |
cypress-3.1.2.tgz | None | |||
CVE-402712-500231Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> http-signature-1.3.6.tgz -> sshpk-1.17.0.tgz -> ❌ dashdash-1.14.1.tgz (Vulnerable Library) |
9.8 | Transitive dashdash-1.14.1.tgz |
cypress-3.1.2.tgz | None | |||
CVE-295712-399081Path to dependency file: /tests/e2e/package.json Path to vulnerable library: /tests/e2e/package.json Dependency Hierarchy: -> cypress-3.1.2.tgz (Root Library) -> cypress-12.17.4.tgz -> request-2.88.12.tgz -> http-signature-1.3.6.tgz -> sshpk-1.17.0.tgz -> ❌ asn1-0.2.6.tgz (Vulnerable Library) |
9.8 | Transitive asn1-0.2.6.tgz |
cypress-3.1.2.tgz | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-8203 | lodash-4.17.15.tgz |
| CVE-2022-0235 | node-fetch-2.6.0.tgz |
| CVE-2021-23337 | lodash-4.17.15.tgz |
| CVE-2021-33502 | normalize-url-3.3.0.tgz |
| GHSA-8x6c-cv3v-vp6g | cacheable-request-6.1.0.tgz |
| CVE-2025-14505 | elliptic-6.5.2.tgz |
| CVE-2021-33502 | normalize-url-1.9.1.tgz |
| CVE-2024-21538 | cross-spawn-7.0.1.tgz |
| CVE-2020-28469 | glob-parent-5.1.0.tgz |
| CVE-2021-27290 | ssri-7.1.0.tgz |
| CVE-2024-45590 | body-parser-1.19.0.tgz |
| CVE-2021-23424 | ansi-html-0.0.7.tgz |
| CVE-2021-23343 | path-parse-1.0.6.tgz |
| CVE-2020-7733 | ua-parser-js-0.7.20.tgz |
| CVE-2024-42461 | elliptic-6.5.2.tgz |
| CVE-2024-43800 | serve-static-1.14.1.tgz |
| CVE-2022-24999 | qs-6.7.0.tgz |
| CVE-587792-470342 | on-finished-2.3.0.tgz |
| CVE-2020-13822 | elliptic-6.5.2.tgz |
| CVE-2022-25881 | http-cache-semantics-4.1.0.tgz |
| CVE-2021-37701 | tar-4.4.8.tgz |
| CVE-2024-9506 | vue-template-compiler-2.6.10.tgz |
| CVE-796484-931798 | lodash-4.17.15.tgz |
| CVE-2022-46175 | json5-2.1.1.tgz |
| CVE-2021-23364 | browserslist-4.8.2.tgz |
| CVE-2021-29060 | color-string-1.5.3.tgz |
| CVE-2020-28500 | lodash-4.17.15.tgz |
| CVE-2021-33587 | css-what-2.1.3.tgz |
| CVE-2020-8116 | dot-prop-4.2.0.tgz |
| CVE-2021-29059 | is-svg-3.0.0.tgz |
| CVE-2021-3807 | ansi-regex-5.0.0.tgz |
| CVE-2025-26862 | urllib3-2.2.3-py3-none-any.whl |
| CVE-2021-33587 | css-what-3.2.1.tgz |
| CVE-2020-15168 | node-fetch-2.6.0.tgz |
| CVE-2025-13466 | body-parser-1.19.0.tgz |
| CVE-2025-6545 | pbkdf2-3.0.17.tgz |
| WS-2020-0042 | acorn-6.3.0.tgz |
| GHSA-7fhm-mqm4-2wp7 | minimist-0.0.8.tgz |
| CVE-2026-21441 | urllib3-2.2.3-py3-none-any.whl |
| WS-2019-0424 | elliptic-6.5.2.tgz |
| CVE-2020-28498 | elliptic-6.5.2.tgz |
| CVE-2022-25927 | ua-parser-js-0.7.20.tgz |
| CVE-2021-37712 | tar-4.4.8.tgz |
| GHSA-6chw-6frg-f759 | acorn-6.3.0.tgz |
| CVE-2022-37620 | html-minifier-4.0.0.tgz |
| CVE-2020-7660 | serialize-javascript-1.9.1.tgz |
| CVE-2021-23382 | postcss-7.0.24.tgz |
| CVE-2024-42459 | elliptic-6.5.2.tgz |
| CVE-2024-34343 | nuxt-2.10.2.tgz |
| CVE-2024-9506 | vue-server-renderer-2.6.10.tgz |
| WS-2021-0152 | color-string-1.5.3.tgz |
| CVE-2024-43796 | express-4.17.1.tgz |
| CVE-2024-42460 | elliptic-6.5.2.tgz |
| CVE-2021-28092 | is-svg-3.0.0.tgz |
| GHSA-7fhm-mqm4-2wp7 | acorn-6.3.0.tgz |
| CVE-2020-7793 | ua-parser-js-0.7.20.tgz |
| CVE-2021-27292 | ua-parser-js-0.7.20.tgz |
| CVE-2025-50182 | urllib3-2.2.3-py3-none-any.whl |
| GHSA-7fhm-mqm4-2wp7 | minimist-1.2.0.tgz |
| CVE-2021-37713 | tar-4.4.8.tgz |
| CVE-2024-43788 | webpack-4.41.2.tgz |
| CVE-2024-47081 | requests-2.32.3-py3-none-any.whl |
| CVE-2022-37598 | uglify-js-3.7.2.tgz |
| CVE-2024-6783 | vue-2.6.10.tgz |
| CVE-2020-7660 | serialize-javascript-2.1.2.tgz |
| CVE-2025-6547 | pbkdf2-3.0.17.tgz |
| CVE-2021-32640 | ws-6.2.1.tgz |
| CVE-2021-32804 | tar-4.4.8.tgz |
| CVE-2025-66471 | urllib3-2.2.3-py3-none-any.whl |
| CVE-2026-2739 | bn.js-4.11.8.tgz |
| CVE-2021-23368 | postcss-7.0.24.tgz |
| CVE-2024-47764 | cookie-0.4.0.tgz |
| CVE-2025-15284 | qs-6.7.0.tgz |
| CVE-2022-25883 | semver-5.7.0.tgz |
| CVE-2021-32803 | tar-4.4.8.tgz |
| CVE-2021-42740 | shell-quote-1.7.2.tgz |
| CVE-2026-2391 | qs-6.7.0.tgz |
| CVE-2024-9506 | vue-2.6.10.tgz |
| CVE-2024-10491 | express-4.17.1.tgz |
| CVE-2025-50181 | urllib3-2.2.3-py3-none-any.whl |
Base branch total remaining vulnerabilities: 235
Base branch commit: c3bfeab8ee549fbc0a78e721eeab90ec8dc4e9ce
Total libraries scanned: 2342
Scan token: 8b26ffc4e5c2403ba47a3698e7dffc81