PT-2026-48868 · Nuxt · @Nuxt/Rspack-Builder+1

·

CVE-2026-49993

·

Published

2026-05-19

·

Updated

2026-06-16

CVSS v4.0

5.9

Medium

VectorAV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @nuxt/rspack-builder versions 3.15.4 through 3.21.6 @nuxt/rspack-builder versions 4.0.0 through 4.4.6 @nuxt/webpack-builder versions 3.15.4 through 3.21.6 @nuxt/webpack-builder versions 4.0.0 through 4.4.6
Description An incomplete fix in the webpack and rspack builders allows source code to be stolen during development. This occurs if the development server is bound to a non-loopback address, such as when using the nuxt dev --host command, and a developer visits a malicious website on the same network.
Recommendations Update versions 3.15.4 through 3.21.6 to 3.21.7. Update versions 4.0.0 through 4.4.6 to 4.4.7.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49993
GHSA-6M52-M754-PW2G
GHSA-X6QJ-4H56-5RJ5

Affected Products

@Nuxt/Rspack-Builder
@Nuxt/Webpack-Builder