Nuxt has released security patch versions 4.5.1 and 3.21.10, along with @nuxt/devtools 3.3.1, addressing multiple vulnerabilities. Key fixes include: a high-severity server-side RCE via server island props when vue.runtimeCompiler is enabled; a medium-severity unauthorized component instantiation via polymorphic 'as' props; a high-severity route rule authorization bypass affecting case-sensitive route rules; server component DoS via the /__nuxt_island endpoint; a high-severity cross-user payload disclosure on cached pages (4.x only); a low-severity dev server path disclosure; and a critical dev-only RCE in Nuxt DevTools via an unauthenticated RPC method over the Vite HMR socket. Immediate upgrade is strongly recommended.
718 Impressions