CVE-2025-24360

MEDIUM

Nuxt Vite-builder < 3.15.3 - Information Disclosure

Title source: rule
STIX 2.1

Description

Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings. Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites. Version 3.15.3 fixes the vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0031
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
nuxt/nuxt >= 3.8.1, < 3.15.3
nuxt/vite-builder 3.8.1 - 3.15.3npm
Published Jan 25, 2025
Tracked Since Feb 18, 2026