Vulnerabilities/

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

Severity:
High

Description

Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin.

Recommendation

Update the @nuxt/devtools package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nuxt/devtools
Anything's wrong? Let us know Last updated on August 05, 2026