Junglewise Threat Intelligence

CVE-2025-24360: Nuxt @nuxt/vite-builder permissive CORS policy in development server

CVE-2025-24360 · Severity: low · CVSS 3.1 · Published 2025-01-27

Vendors: npm, Nuxt.

Executive brief

Nuxt is a popular web development framework. A security issue in its development server allows malicious websites to bypass security restrictions and read the source code of a project while a developer is working on it. This could lead to the exposure of sensitive intellectual property or application logic if a developer visits a compromised site while their local development environment is active.

Technical details

The Nuxt development server, specifically when using the @nuxt/vite-builder, implements a custom CORS handler that defaults to 'Access-Control-Allow-Origin: *'. This configuration allows any external origin to perform fetch requests against the local development server (typically localhost:3000). An attacker can exploit this by tricking a developer into visiting a malicious website, which then uses JavaScript to read source files (e.g., app.vue) or manifest data from the dev server. The vulnerability is also potentially susceptible to DNS rebinding due to a lack of Host header validation. The issue is fixed in version 3.15.3; users on older versions can mitigate the risk by manually configuring 'vite.server.cors' to a restrictive value.

Affected products

  • Nuxt @nuxt/vite-builder >=3.8.1, <3.15.3

Timeline

  • 2023-10-28: other: Vulnerable CORS handler introduced in PR #23995
  • 2025-01-24: advisory: GitHub Advisory published
  • 2025-01-25: other: NVD published date
  • 2025-01-27: patched: Fix released in version 3.15.3

References