THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-279x-mwfv-vcqv (critical) — Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

[GHSA] GHSA-279x-mwfv-vcqv (critical) — Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

highgithub_advisoriesPublished 2026-08-05

GHSA-279x-mwfv-vcqv Severity: critical CVE: CVE-2026-71319

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

### Impact

Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR e

Indicators of compromise

Original source: https://github.com/advisories/GHSA-279x-mwfv-vcqv