News
Nuxt Patches Eight Advisories Including a Critical DevTools RCE and Server-Side RCE via Server Island Props
Nuxt released 4.5.1, 3.21.10, and @nuxt/devtools 3.3.1 on July 27 covering eight security advisories. The most severe are GHSA-279x-mwfv-vcqv (critical, RCE in DevTools, development-only), GHSA-9473-5f9j-94wq (high, server-side RCE via server island props, affecting production), GHSA-hxvh-4h3w-prp9 (high, route rule authorization bypass), and GHSA-wm8w-6qjm-cv43 (high, cross-user disclosure of cached payloads). The production RCE required platform-wide mitigations before public disclosure — if you run Nuxt, this is a same-day patch, not a next-sprint item.
↳ Follow the thread