Intel

AIKIDO-2026-10263

@nuxtjs/plausible is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data Authenticity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 27, 2026

65

Medium Risk

This Affects:

JS@nuxtjs/plausible
0.0.0 - 3.0.0
Fixed in 3.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package improperly trust or fail to sanitize cf-connecting-ip and x-real-ip headers, allowing client-controlled IP spoofing through proxy header sniffing. An attacker may inject crafted headers to impersonate arbitrary IP addresses, bypass IP-based access controls, rate limiting, logging, or security policies. This can enable unauthorized access, evade detection mechanisms, or manipulate audit trails if the application relies on these headers for client identity validation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@nuxtjs/plausible is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.0 - 3.0.0.

How to fix this

Upgrade the @nuxtjs/plausible library to the patch version.