nuxt is vulnerable to Sensitive Information Disclosure
75
High Risk
Nuxt contains an information disclosure vulnerability affecting runtime payload extraction for cached pages. When route caching (cache, swr, or isr) is enabled, authenticated user data stored in /_payload.json may be cached without considering authentication or cache variation, allowing unauthenticated users or other authenticated users to retrieve another user's server-rendered data.
You are affected if you are using a version that falls within the vulnerable range and have route caching (cache, swr, or isr) enabled for authenticated pages.
nuxt is vulnerable to Sensitive Information Disclosure in versions 4.4.0 - 4.5.0.
Upgrade to a patched version. If this is not possible, disable experimental.payloadExtraction, avoid enabling route caching for authenticated pages, protect /**/_payload.json behind authentication, and purge any existing cached payloads after applying the fix.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant