CVE-2025-24360: Opening a malicious website while running a Nuxt dev server could allow read-only access to code

Published Jan 25, 2025
·
Updated

Summary Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings.

Details While Vite patched the default CORS settings to fix https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6, nuxt uses its own CORS handler by default (https://github.com/nuxt/nuxt/pull/23995).

https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/client.ts#L257-L263

That CORS handler sets Access-Control-Allow-Origin: .

> [!IMPORTANT] > If on an affected version, it may be possible to opt-out of the default Nuxt CORS handler by configuring vite.server.cors.

PoC 1. Start a dev server in any nuxt project using Vite by nuxt dev. 2. Send a fetch request to http://localhost:3000/nuxt/app.vue (fetch('http://localhost:3000/nuxt/app.vue')) from a different origin page.

Impact Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites

Additional Information /nuxtvitenode/manifest / /nuxtvitenode/module also seems to have Access-Control-Allow-Origin: , so it maybe also possible to exploit that handler. https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/vite-node.ts#L39 Although I didn't find a valid module id. Note that this handler is probably also vulnerable to DNS rebinding attacks as I didn't find any host header checks.

Other sources

Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings. Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites. Version 3.15.3 fixes the vulnerability.

MITRE

Affected Software

2 affected componentsFixes available
npm/@nuxt/vite-builder>=3.8.1<3.15.3
3.15.3
Nuxt.js>=3.8.1<3.15.3

Event History

Jan 25, 2025
CVE Published
via MITRE·12:49 AM
Data Sourced
via MITRE·12:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Jan 27, 2025
Advisory Published
via GitHub·11:31 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-24360?

CVE-2025-24360 is considered a medium severity vulnerability due to insecure default CORS settings.

2

How do I fix CVE-2025-24360?

To resolve CVE-2025-24360, upgrade to @nuxt/vite-builder version 3.15.3 or higher.

3

What is the impact of CVE-2025-24360?

CVE-2025-24360 allows unauthorized websites to send requests to the Nuxt development server and read the responses.

4

Which versions of Nuxt are affected by CVE-2025-24360?

CVE-2025-24360 affects Nuxt versions between 3.8.1 and 3.15.3.

5

Is CVE-2025-24360 a client-side or server-side vulnerability?

CVE-2025-24360 is a server-side vulnerability related to the development server's CORS configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203