Executive brief
Nuxt is a popular web development framework. A security issue in its development server allows malicious websites to bypass security restrictions and read the source code of a project while a developer is working on it. This could lead to the exposure of sensitive intellectual property or application logic if a developer visits a compromised site while their local development environment is active.
Technical details
The Nuxt development server, specifically when using the @nuxt/vite-builder, implements a custom CORS handler that defaults to 'Access-Control-Allow-Origin: *'. This configuration allows any external origin to perform fetch requests against the local development server (typically localhost:3000). An attacker can exploit this by tricking a developer into visiting a malicious website, which then uses JavaScript to read source files (e.g., app.vue) or manifest data from the dev server. The vulnerability is also potentially susceptible to DNS rebinding due to a lack of Host header validation. The issue is fixed in version 3.15.3; users on older versions can mitigate the risk by manually configuring 'vite.server.cors' to a restrictive value.
Affected products
- Nuxt @nuxt/vite-builder >=3.8.1, <3.15.3
Timeline
- 2023-10-28: other: Vulnerable CORS handler introduced in PR #23995
- 2025-01-24: advisory: GitHub Advisory published
- 2025-01-25: other: NVD published date
- 2025-01-27: patched: Fix released in version 3.15.3
References
- https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47
- https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6
- https://github.com/nuxt/nuxt/pull/23995
- https://github.com/nuxt/nuxt/commit/7eeb910bf4accb1e0193b9178c746f06ad3dd88f
- https://github.com/nuxt/nuxt
- https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/client.ts