@nuxt/nitro-server is vulnerable to Authentication Bypass
63
Medium Risk
When component islands are enabled, .server.vue pages are exposed via /__nuxt_island/page_* and rendered by the Nitro island handler. Before the fix, the handler rendered page islands without the Vue Router middleware chain, so middleware-only auth checks did not run. The island handler now propagates middleware-issued ~renderResponse results instead of rendering protected content for unauthorized requests.
You are affected if you are using a version that falls within the vulnerable range.
@nuxt/nitro-server is vulnerable to Authentication Bypass in versions 3.20.0 - 3.21.5 and 4.2.0 - 4.4.5.
Upgrade the @nuxt/nitro-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant