github.com
https://github.com/nuxt/nuxt CVE-2025-24360
MEDIUM
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
Record summary
CVE-2025-24360 has a selected CVSS score of 5.3 (medium).
Description
Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings. Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites. Version 3.15.3 fixes the vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 3.8.1, < 3.15.3 | affected | |
@nuxt/vite-builderBrowse npm / @nuxt/vite-builder | GitHub Advisory | 3.8.1 to < 3.15.3 · Fixed in 3.15.3 | affected |
References
8github.com
https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/client.ts github.com
https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/vite-node.ts github.com
https://github.com/nuxt/nuxt/commit/7eeb910bf4accb1e0193b9178c746f06ad3dd88f github.com
https://github.com/nuxt/nuxt/pull/23995 github.comConfirmation
https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47 github.com
https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-24360