CVE-2025-24360
Description
Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings. Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites. Version 3.15.3 fixes the vulnerability.
CWE
- CWE-200 — CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Affected
- nuxt / nuxt — v=>= 3.8.1, < 3.15.3 [affected]
CVSS
- 3.1 score=5.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
References
- https://github.com/nuxt/nuxt/security/advisories/GHSA-2452-6xj8-jh47 x_refsource_CONFIRM
- https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 x_refsource_MISC
- https://github.com/nuxt/nuxt/pull/23995 x_refsource_MISC
- https://github.com/nuxt/nuxt/commit/7eeb910bf4accb1e0193b9178c746f06ad3dd88f x_refsource_MISC
- https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/client.ts#L257-L263 x_refsource_MISC
- https://github.com/nuxt/nuxt/blob/7d345c71462d90187fd09c96c7692f306c90def5/packages/vite/src/vite-node.ts#L39 x_refsource_MISC
Source
cvelistV5-main/cves/2025/24xxx/CVE-2025-24360.json