---
title: "Nuxt Security Patch Releases · Nuxt Blog"
url: https://daily.dev/posts/nuxt-security-patch-releases-nuxt-blog-l7nm4rbdb
source_url: https://nuxt.com/blog/v4-5-security
type: article
source: "Nuxt"
published: 2026-07-27T10:30:07.430Z
updated: 2026-07-31T16:42:50.577Z
tags: ["security", "webdev", "vuejs", "nuxt"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Nuxt Security Patch Releases · Nuxt Blog

**[Nuxt](https://daily.dev/sources/nuxt_source)** · 4 min read · 0 upvotes · 0 comments

## Summary

Nuxt has released security patch versions 4.5.1 and 3.21.10, along with @nuxt/devtools 3.3.1, addressing multiple vulnerabilities. Key fixes include: a high-severity server-side RCE via server island props when vue.runtimeCompiler is enabled; a medium-severity unauthorized component instantiation via polymorphic 'as' props; a high-severity route rule authorization bypass affecting case-sensitive route rules; server component DoS via the /__nuxt_island endpoint; a high-severity cross-user payload disclosure on cached pages (4.x only); a low-severity dev server path disclosure; and a critical dev-only RCE in Nuxt DevTools via an unauthenticated RPC method over the Vite HMR socket. Immediate upgrade is strongly recommended.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://nuxt.com/blog/v4-5-security>

---

Tags: [#security](https://daily.dev/tags/security), [#webdev](https://daily.dev/tags/webdev), [#vuejs](https://daily.dev/tags/vuejs), [#nuxt](https://daily.dev/tags/nuxt)

[View this post on daily.dev](https://daily.dev/posts/nuxt-security-patch-releases-nuxt-blog-l7nm4rbdb)
