Vulnerabilities/

Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder

Severity:
Medium

Description

Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings.

Recommendation

Update the @nuxt/vite-builder package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nuxt/vite-builder
Anything's wrong? Let us know Last updated on January 27, 2025