Update dependency vuetify to v3 [SECURITY]#82
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 5, 2026 10:18
7bcb9e4 to
867ab3f
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 5, 2026 20:44
867ab3f to
82056cc
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 13, 2026 17:08
82056cc to
d95a88a
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 13, 2026 21:54
d95a88a to
171ce4d
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 26, 2026 18:15
171ce4d to
5258b5e
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
March 26, 2026 22:31
5258b5e to
9bef6c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
3 times, most recently
from
April 1, 2026 20:53
454e562 to
dcf05bf
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 2, 2026 01:22
dcf05bf to
0ecd715
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 8, 2026 18:54
0ecd715 to
bf1552d
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 8, 2026 23:06
bf1552d to
4a440a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 15, 2026 10:19
4a440a8 to
c31ceb7
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 16, 2026 09:54
c31ceb7 to
4a7780e
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 23, 2026 19:11
53456aa to
12df7cf
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 29, 2026 10:06
12df7cf to
f4ea2a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 29, 2026 20:33
f4ea2a9 to
a7d635d
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 30, 2026 16:28
a7d635d to
0a3bc1b
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
April 30, 2026 23:30
0a3bc1b to
67e5371
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 12, 2026 16:43
67e5371 to
132cca7
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
2 times, most recently
from
May 14, 2026 18:48
6cdd119 to
e089bdf
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 14, 2026 21:00
e089bdf to
fb5cfce
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 18, 2026 18:14
fb5cfce to
095a513
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 18, 2026 23:42
095a513 to
b894415
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 22, 2026 17:35
b894415 to
d70b7b2
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 22, 2026 22:05
d70b7b2 to
7b527d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 28, 2026 18:12
7b527d4 to
9132e66
Compare
renovate
Bot
force-pushed
the
renovate/npm-vuetify-vulnerability
branch
from
May 29, 2026 00:50
9132e66 to
b69030f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.4.0→^3.0.0Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component
CVE-2025-8082 / GHSA-9w3x-85mw-4fwm
More information
Details
Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss attack. The vulnerability occurs because the 'title-date-format' property of the 'VDatePicker' can accept a user created function and assign its output to the 'innerHTML' property of the title element without sanitization.
This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0.
Note:
Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vuetifyjs/vuetify (vuetify)
v3.0.0Compare Source
v3.0.0 (Titan)
Welcome to the v3.0.0 release of Vuetify!
Supporting Vuetify
Vuetify is an open source MIT project that has been made possible due to the generous contributions by sponsors and backers. If you are interested in supporting this project, please consider:
❗️ Important Links
💯 Release notes
🚀 Features
🔧 Bug Fixes
v2.7.2Compare Source
🔧 Bug Fixes
v2.7.1Compare Source
🔧 Bug Fixes
v2.7.0Compare Source
🚀 Features
🔧 Bug Fixes
v2.6.16Compare Source
🔧 Bug Fixes
v2.6.15Compare Source
🔧 Bug Fixes
v2.6.14Compare Source
🔧 Bug Fixes
v2.6.13Compare Source
🔧 Bug Fixes
v2.6.12Compare Source
🔧 Bug Fixes
v2.6.11Compare Source
🔧 Bug Fixes
v2.6.10Compare Source
🔧 Bug Fixes
tabindex="-1"or hidden inputs (89e3850), closes #15745🔬 Code Refactoring
BREAKING CHANGES
eventNamefunction can no longer render arbitrary HTML, convert to VNodes instead.eventSummarycan no longer be used with v-html, replace with<component :is="{ render: eventSummary }" />v2.6.9Compare Source
🔧 Bug Fixes
v2.6.8Compare Source
🔧 Bug Fixes
v2.6.7Compare Source
🔧 Bug Fixes
v2.6.6Compare Source
🔧 Bug Fixes
🔬 Code Refactoring
v2.6.5Compare Source
🔧 Bug Fixes
v2.6.4Compare Source
🔧 Bug Fixes
v2.6.3Compare Source
🔧 Bug Fixes
v2.6.2Compare Source
🔧 Bug Fixes
otpwhenvaluechanges (#14460) (c58f02a), closes #14437v2.6.1Compare Source
🔧 Bug Fixes
ittranslations (#14398) (33385d5)v2.6.0Compare Source
v2.6.0 (Horizon)
Welcome to the v2.6.0 release of Vuetify!
❗️ Important Links
🤚 FAQ
💪 Support Vuetify Development
Vuetify is an open source MIT project that has been made possible due to the generous contributions by our sponsors and backers. If you are interested in supporting this project, please consider:
💯 Release notes
🔧 Bug Fixes
🚀 Features
<td>or<th>element (a4b8856), closes #8474 #12791v2.6.0.beta.0 - v2.6.0
Includes bugfixes from 2.5.11 to 2.5.14
🚀 Features
v2.5.14Compare Source
🔧 Bug Fixes
v2.5.13Compare Source
🔧 Bug Fixes
<select multiple>in safari (0ca7d0d), closes #9470v2.5.12Compare Source
🔧 Bug Fixes
v2.5.11Compare Source
🔧 Bug Fixes
v2.5.10Compare Source
🔧 Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.