GHSA-279x-mwfv-vcqv
CRITICALCVE-2026-71319Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions
- Affected
- >=0, <3.3.1, < 3.3.1
- Fixed in
- 3.3.1
- Weakness
- CWE-94
- Published
- 2026-08-05
- Source
- osv