Missing Authentication for Critical Function Affecting @nuxt/devtools package, versions <3.3.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-NUXTDEVTOOLS-18565128
  • published6 Aug 2026
  • disclosed5 Aug 2026
  • creditTazmi, Ngo Phuc Duong

Introduced: 5 Aug 2026

NewCVE-2026-71319  (opens in a new tab)
CWE-306  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade @nuxt/devtools to version 3.3.1 or higher.

Overview

@nuxt/devtools is a Nuxt DevTools

Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the nuxt:devtools:rpc. An attacker can execute arbitrary commands on the host system by sending crafted RPC calls to the exposed WebSocket endpoint without authentication.

Note: This is only exploitable if the development server is running and accessible to the attacker, such as when bound to a non-loopback interface or when the developer visits a malicious website while the server is active.

Workaround

This vulnerability can be mitigated by disabling DevTools entirely with the configuration option devtools: { enabled: false } or by avoiding running the development server on a non-loopback interface in untrusted environments.

CVSS Base Scores

version 4.0
version 3.1