Nuxt — CWE-24

All FrameworksNuxtCWE-24

1 CVEs categorized as CWE-24 in Nuxt.

CVE-2024-23657HIGH2024
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the WebSocket handler, an attac…