Nuxt has released security updates (versions 4.5.1 and 3.21.10) addressing eight vulnerabilities including server-side remote code execution via server island props, authorization bypass, denial of service, cross-user payload disclosure, and a critical RCE in @nuxt/devtools 3.3.1. The most severe production issue (GHSA-9473-5f9j-94wq) requires vue.runtimeCompiler to be enabled and allows RCE through attacker-controlled island props. Socket has published free Certified Patches for two of the disclosed advisories, applicable via `socket patch add <GHSA-ID>`, and is preparing patches for the rest. Teams using authenticated pages with Nuxt caching should also purge CDN/edge caches after upgrading.

4m read timeFrom socket.dev
Post cover image
Table of contents
Impact #Upgrade Nuxt and Nuxt DevTools #Free Socket Certified Patches Available #Recommended Actions #
8 Impressions