๐Ÿ” CVE Alert

CVE-2026-49993

UNKNOWN 0.0

@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
7th

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. nuxt dev --host) and the developer opens a malicious site on the same network. This issue has been patched in versions 3.21.7 and 4.4.7.

CWE CWE-749
Vendor nuxt
Product nuxt
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for nuxt nuxt

Be the first to know when new unknown vulnerabilities affecting nuxt nuxt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

nuxt / nuxt
>= 3.15.4, < 3.21.7 >= 4.0.0, < 4.4.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nuxt/nuxt/security/advisories/GHSA-x6qj-4h56-5rj5 github.com: https://github.com/nuxt/nuxt/security/advisories/GHSA-6m52-m754-pw2g github.com: https://github.com/nuxt/nuxt/pull/35200 github.com: https://github.com/nuxt/nuxt/commit/77187ee4015e9267fb464951542a3e09e8b5fa05 github.com: https://github.com/nuxt/nuxt/commit/e351de943e82db16970618b60dc7fdbaa58630f3