Executive brief
Nuxt is a popular web development framework. A security flaw in its development tools could allow a malicious website to steal a developer's source code if they are running a development server on their local network. This occurs when the developer hosts their project on a non-private address and visits a compromised site, potentially exposing intellectual property or sensitive configuration details.
Technical details
This vulnerability is an incomplete fix for a previous issue (GHSA-4gf7-ff8x-hq99). The original mitigation relied on 'Sec-Fetch-Mode' and 'Sec-Fetch-Site' headers to enforce same-origin checks; however, browsers do not send these headers for non-trustworthy origins (such as plain IP addresses on a local network). If a developer runs 'nuxt dev --host' and visits a malicious site, the attacker can use a script tag to load the application bundle and extract source code using 'Function.prototype.toString' on the webpack/rspack chunk global. The vulnerability is patched in versions 3.21.6 and 4.4.6 by falling back to 'Origin', 'Referer', and 'Host' header comparisons when 'Sec-Fetch' headers are missing.
Affected products
- Nuxt @nuxt/rspack-builder 3.15.4 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
- Nuxt @nuxt/webpack-builder 3.15.4 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
Timeline
- 2025-01-24: advisory: Original vulnerability GHSA-4gf7-ff8x-hq99 disclosed
- 2026-05-11: patched: Fix merged in PR #35051
- 2026-06-12: disclosed: CVE-2026-45670 published