Executive brief
Nuxt is a popular web framework for building Vue.js applications. A vulnerability in its Island prerendering feature allows attackers who control an API endpoint to craft malicious responses that cause client browsers to make unintended requests to different parts of the same application. This requires the app to be prerendered, the attacker to control an API response, and a user to navigate to the prerendered page, making it a limited-impact issue with low practical risk.
Technical details
A client-side path traversal vulnerability exists in Nuxt's Island payload revival mechanism (revive-payload.client.ts). During prerendering, if an API endpoint returns user-controlled data with a crafted __nuxt_island object containing path traversal sequences in the "key" field, the client will deserialize this payload and attempt to fetch /__nuxt_island/${key}.json, potentially traversing to unintended endpoints. The attack requires three conditions: prerendering enabled, attacker control over an API response called during prerendering, and client-side navigation to the prerendered page. The vulnerability is mitigated by strict validation of Island keys (alphanumeric with hyphens, max 100 chars). Patches are available in Nuxt 3.19.0+ and 4.1.0+.
Affected products
- Nuxt Nuxt 3.6.0-3.18.x, 4.0.0-4.0.x
Timeline
- 2025-09-17: disclosed: Advisory published
- 2025-09-17: patched: Patch released in versions 3.19.0 and 4.1.0