PT-2026-70157 · Nuxt · Nuxt
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nuxt versions 4.4.7 through 4.5.0
Nuxt versions 3.21.7 through 3.21.9
Description
An information disclosure issue exists in the development server's Chrome DevTools workspace endpoint 'GET /.well-known/appspecific/com.chrome.devtools.json'. The local-request gate
isLocalDevRequest() relies on the Host header instead of the connected peer address. If the development server is bound to a network-reachable interface and experimental.chromeDevtoolsProjectSettings is enabled, an unauthenticated attacker on the local network can spoof the Host header to retrieve the project's absolute filesystem root path rootDir and a persistent per-project workspace UUID.Recommendations
Update to version 4.5.1 or later.
Update to version 3.21.10 or later.
Disable the
experimental.chromeDevtoolsProjectSettings setting to mitigate the risk.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuxt