THREAT OPS › Threat News › [GHSA] GHSA-279x-mwfv-vcqv (critical) — Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
[GHSA] GHSA-279x-mwfv-vcqv (critical) — Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
GHSA-279x-mwfv-vcqv Severity: critical CVE: CVE-2026-71319
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
### Impact
Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR e
Indicators of compromise
- CVE-2026-71319cve
- https://www.npmjs.com/package/launch-editorurl
Original source: https://github.com/advisories/GHSA-279x-mwfv-vcqv