Junglewise Threat Intelligence

CVE-2026-45670: Nuxt source code disclosure in webpack and rspack builders

CVE-2026-45670 · Severity: medium · CVSS 3.1 · Published 2026-06-12

Technologies: Nuxt Webpack Builder, Nuxt Rspack Builder. Vendors: Nuxt.

Executive brief

Nuxt is a popular web development framework. A security flaw in its development tools could allow a malicious website to steal a developer's source code if they are running a development server on their local network. This occurs when the developer hosts their project on a non-private address and visits a compromised site, potentially exposing intellectual property or sensitive configuration details.

Technical details

This vulnerability is an incomplete fix for a previous issue (GHSA-4gf7-ff8x-hq99). The original mitigation relied on 'Sec-Fetch-Mode' and 'Sec-Fetch-Site' headers to enforce same-origin checks; however, browsers do not send these headers for non-trustworthy origins (such as plain IP addresses on a local network). If a developer runs 'nuxt dev --host' and visits a malicious site, the attacker can use a script tag to load the application bundle and extract source code using 'Function.prototype.toString' on the webpack/rspack chunk global. The vulnerability is patched in versions 3.21.6 and 4.4.6 by falling back to 'Origin', 'Referer', and 'Host' header comparisons when 'Sec-Fetch' headers are missing.

Affected products

  • Nuxt @nuxt/rspack-builder 3.15.4 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
  • Nuxt @nuxt/webpack-builder 3.15.4 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6

Timeline

  • 2025-01-24: advisory: Original vulnerability GHSA-4gf7-ff8x-hq99 disclosed
  • 2026-05-11: patched: Fix merged in PR #35051
  • 2026-06-12: disclosed: CVE-2026-45670 published

References

Related threats