Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities
Brief
Nuxt has released security updates for multiple vulnerabilities affecting Nuxt 3. x and 4. x, along with a separate critical development-only vulnerability in @nuxt/devtools .
Nuxt 4.
- 1 and 3.
- 10 address issues including server-side remote code execution, authorization bypass, denial of service, and cross-user payload disclosure. @nuxt/devtools 3.
- 1 fixes a critical remote code execution vulnerability affecting development servers.
Socket has published Certified Patches for two of the disclosed Nuxt advisories and is preparing patches for the remaining issues. Certified Patches for Critical and High severity vulnerabilities are free to use, including for teams that are not Socket customers.
Impact
#
The Nuxt release addresses eight GitHub Security Advisories across Nuxt and Nuxt DevTools.
