The Nuxt team has disclosed several security vulnerabilities fixed in Nuxt 4.5.1 and 3.21.10, ranging from a high-severity server-side remote code execution (under specific conditions) to lower-severity and development-only issues. Here’s what Netlify customers need to know. Vulnerabilities
Continue reading...
- GHSA-9473-5f9j-94wq (High): remote code execution via server island props
- GHSA-48hr-524c-v5w3 (Medium): unauthorized component instantiation via server island props
- GHSA-hxvh-4h3w-prp9 (High): route rule authorization bypass when a route rule key contains an uppercase character
- GHSA-hxcr-hm88-mpq6 and GHSA-9pgf-384g-p7mv (High): server component denial of service
- GHSA-wm8w-6qjm-cv43 (High): cross-user disclosure of cached payloads (Nuxt 4.x only, 4.4.0 and later)
- GHSA-7c4v-fwgw-9rf7 (Low): dev server path disclosure
- GHSA-279x-mwfv-vcqv (Critical, development only): remote code execution in Nuxt DevTools, fixed in @nuxt/devtools@3.3.1
- nuxt 4.5.1 or later (for Nuxt 4)
- nuxt 3.21.10 or later (for Nuxt 3)
- Nuxt security post
- Nuxt security advisories
Continue reading...