GHSA-6m52-m754-pw2g
MODERATECVE-2026-45670This is an incomplete fix for [GHSA-4gf7-ff8x-hq99](https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99). Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network.
- Affected
- >=3.15.4, <3.21.6, >= 3.15.4, <= 3.21.5
- Fixed in
- 3.21.6
- Weakness
- CWE-749
- Published
- 2026-05-19
- Source
- osv