Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities
ID: 52eee4a3-daec-50ed-99a3-5996c7b2acb9
STIX ID: report--52eee4a3-daec-50ed-99a3-5996c7b2acb9
Feed Name: Socket Blog
Nuxt released patches addressing eight GitHub Security Advisories across Nuxt and Nuxt DevTools — notably a high-severity server-side RCE via server island props (requires vue.runtimeCompiler and certain app patterns), an unauthorized component-instantiation issue, authorization-bypass, DoS flaws, cached payload disclosure on authenticated pages, and a development-only critical RCE in @nuxt/devtools; upgrades (Nuxt 4.5.1 / 3.21.10 and devtools 3.3.1), Socket Certified Patches, lockfile refreshes, cache purges, and avoiding exposed dev servers are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
