logo

Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities

ID: 52eee4a3-daec-50ed-99a3-5996c7b2acb9

STIX ID: report--52eee4a3-daec-50ed-99a3-5996c7b2acb9

Feed Name: Socket Blog

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Wenxin Jiang

...
...

Nuxt released patches addressing eight GitHub Security Advisories across Nuxt and Nuxt DevTools — notably a high-severity server-side RCE via server island props (requires vue.runtimeCompiler and certain app patterns), an unauthorized component-instantiation issue, authorization-bypass, DoS flaws, cached payload disclosure on authenticated pages, and a development-only critical RCE in @nuxt/devtools; upgrades (Nuxt 4.5.1 / 3.21.10 and devtools 3.3.1), Socket Certified Patches, lockfile refreshes, cache purges, and avoiding exposed dev servers are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.