Description
Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin.
Recommendation
Update the @nuxt/devtools package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.3.1
- Patched version(s): 3.3.1
References
Could your website be exposed too?
SmartScanner can check your website for Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution - CVE-2026-24737
- @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution - CVE-2026-54658
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
You might also like:
See something that needs correcting? Let us knowUpdated August 05, 2026


