THREAT OPS › Threat News › [GHSA] GHSA-7c4v-fwgw-9rf7 (medium) — Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
[GHSA] GHSA-7c4v-fwgw-9rf7 (medium) — Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-7c4v-fwgw-9rf7 Severity: medium CVE: None
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
### Impact
When a Nuxt dev server is bound to a network-reachable interface (for example `nuxt dev --host` for on-device testing), the default-enabled Chrome DevTools workspace endpoint `GET /.well-known/appspecific/com.chrome.devtools.json` returns
Original source: https://github.com/advisories/GHSA-7c4v-fwgw-9rf7