THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7c4v-fwgw-9rf7 (medium) — Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

[GHSA] GHSA-7c4v-fwgw-9rf7 (medium) — Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

medgithub_advisoriesPublished 2026-08-07

GHSA-7c4v-fwgw-9rf7 Severity: medium CVE: None

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

### Impact

When a Nuxt dev server is bound to a network-reachable interface (for example `nuxt dev --host` for on-device testing), the default-enabled Chrome DevTools workspace endpoint `GET /.well-known/appspecific/com.chrome.devtools.json` returns

Original source: https://github.com/advisories/GHSA-7c4v-fwgw-9rf7