Vulnerabilities/

@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Re - @nuxt/webpack-builder

Severity:
Medium

Description

This is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network.

Recommendation

Update the @nuxt/webpack-builder package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nuxt/webpack-builder
Anything's wrong? Let us know Last updated on June 16, 2026