GHSA-x6qj-4h56-5rj5
MODERATECVE-2026-49993This is an incomplete fix for [GHSA-6m52-m754-pw2g](https://github.com/nuxt/nuxt/security/advisories/GHSA-6m52-m754-pw2g). Source code may still be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network.
- Affected
- >= 4.0.0, < 4.4.7
- Fixed in
- 4.4.7
- Weakness
- CWE-749
- Published
- 2026-06-16
- Source
- github