Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
- Severity:
- High
Description
Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin.
Recommendation
Update the @nuxt/devtools package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.3.1
- Patched version(s): 3.3.1
References
Related Issues
- jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution - CVE-2026-24737
- @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution - CVE-2026-54658
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
You might also like:
- Tags:
- npm
- @nuxt/devtools
Anything's wrong? Let us know Last updated on August 05, 2026


