nuxt Vulnerabilities and Affected Products
Vulnerabilities associated with devtools.
Products
Clear product- nuxt26 vulnerabilities
- nuxt/framework3 vulnerabilities
- devtools1 vulnerability
- icon1 vulnerability
- nuxt/nuxt1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-71319CRITICAL | Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionNuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and… | CVSS9.6v3.1 | EPSS0.324% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |