PT-2026-48868 · Nuxt · @Nuxt/Rspack-Builder+1
CVSS v4.0
5.9
Medium
| Vector | AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@nuxt/rspack-builder versions 3.15.4 through 3.21.6
@nuxt/rspack-builder versions 4.0.0 through 4.4.6
@nuxt/webpack-builder versions 3.15.4 through 3.21.6
@nuxt/webpack-builder versions 4.0.0 through 4.4.6
Description
An incomplete fix in the webpack and rspack builders allows source code to be stolen during development. This occurs if the development server is bound to a non-loopback address, such as when using the
nuxt dev --host command, and a developer visits a malicious website on the same network.Recommendations
Update versions 3.15.4 through 3.21.6 to 3.21.7.
Update versions 4.0.0 through 4.4.6 to 4.4.7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Nuxt/Rspack-Builder
@Nuxt/Webpack-Builder