nuxt is vulnerable to Information Disclosure
31
Low Risk
When the Nuxt dev server is bound to a network-reachable interface, the default-enabled Chrome DevTools workspace endpoint returns the absolute project root path and a persistent per-project workspace UUID. The endpoint's local-only gate trusts request headers rather than the connected peer address, so a request with no origin-style headers and a spoofed Host header is treated as local. Any unauthenticated host that can reach the dev server on the network can retrieve the project's filesystem path and workspace UUID. The fix additionally requires the connected TCP peer to be a loopback address, verified from the socket rather than from request headers.
You are affected if you are using a version that falls within the vulnerable range and you run the Nuxt dev server bound to a non-loopback interface on an untrusted network with experimental.chromeDevtoolsProjectSettings enabled.
nuxt is vulnerable to Information Disclosure in versions 4.4.7 - 4.5.0 and 3.21.7 - 3.21.9.
Upgrade the nuxt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant