Nuxt
Nuxt Security Vulnerabilities Require Immediate Attention
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Nuxt has released security patches for versions 4.5.1 and 3.21.10, addressing multiple vulnerabilities including a high-severity server-side remote code execution (RCE) risk. The RCE vulnerability occurs when the Vue runtime compiler is enabled and untrusted input is forwarded to server components. Other issues include authorization bypass due to case-insensitive routing and potential denial-of-service attacks. Users of Nuxt applications, regardless of hosting provider, are affected, particularly those using specific configurations with route rules and server components. The Nuxt team recommends immediate upgrades and auditing of existing configurations to mitigate risks. The vulnerabilities were disclosed on July 27, 2026, with advisories linked to CVEs including GHSA-hxcr-hm88-mpq6 and GHSA-9pgf-384g-p7mv.
Key Points: • Nuxt 4.5.1 and 3.21.10 patches critical vulnerabilities, including server-side RCE. • Vulnerabilities affect applications using Vue's runtime compiler and specific route configurations. • Immediate upgrades and configuration audits are essential to mitigate risks.