Vulnerabilities/

@nuxtlabs/github-module made Use of Hard-coded Credentials

Severity:
High

Description

https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt, nuxtlabs and nuxt-themes GitHub organizations. A patch in version 1.6.2 fixed the issue.

Recommendation

Update the @nuxtlabs/github-module package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nuxtlabs/github-module
Anything's wrong? Let us know Last updated on November 12, 2023