chore(deps): update dependency @nuxt/devtools to v3 [security] - #70
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
November 10, 2025 17:34
1b3964f to
888b45c
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
November 18, 2025 22:41
888b45c to
fede9ad
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
December 3, 2025 18:25
fede9ad to
9bbda56
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
December 31, 2025 20:09
05119f3 to
8fe447d
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
January 8, 2026 18:35
8fe447d to
7095c2d
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
January 23, 2026 18:15
314626a to
f4cd10b
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
February 2, 2026 17:38
f4cd10b to
b69501c
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
February 17, 2026 15:07
e10ac51 to
b0b3eec
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
March 10, 2026 03:23
08f6cf7 to
128031f
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
March 13, 2026 18:36
128031f to
782c989
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
3 times, most recently
from
April 1, 2026 17:03
9ef4055 to
4ffe03b
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
April 8, 2026 21:08
4ffe03b to
105f8af
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
April 29, 2026 13:45
105f8af to
9ae8e35
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
May 18, 2026 10:00
ab59ee4 to
a0d8cdc
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
June 1, 2026 18:48
78ca5bb to
292674e
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
June 13, 2026 16:14
292674e to
423de48
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
July 16, 2026 16:00
d5d59c5 to
957b7f3
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
July 24, 2026 19:55
4ab215d to
ed2511f
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
July 30, 2026 21:42
29d2776 to
4a958cd
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
2 times, most recently
from
August 14, 2026 21:08
bd04d39 to
2cd0fc3
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
August 26, 2026 14:14
2cd0fc3 to
d028428
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
5 times, most recently
from
September 7, 2026 23:17
6190399 to
37bce29
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
3 times, most recently
from
September 15, 2026 13:54
8ce1a02 to
c1f5e18
Compare
renovate
Bot
force-pushed
the
renovate/npm-nuxt-devtools-vulnerability
branch
from
September 16, 2026 06:33
c1f5e18 to
8084c02
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.1.1→^3.0.0Nuxt DevTools vulnerable to cross-site scripting (XSS)
CVE-2025-52662 / GHSA-xmq3-q5pm-rp26
More information
Details
A vulnerability in Nuxt DevTools has been fixed in version 2.6.4*. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
CVE-2026-71319 / GHSA-279x-mwfv-vcqv
More information
Details
Impact
Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the
nuxt:devtools:rpcplugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocolvite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. TheupdateOptions(),clearOptions(), andopenInEditor()methods do not enforce theensureDevAuthTokencheck that the other mutating methods use.openInEditor()reads the persistedbehavior.openInEditorvalue and passes it to thelaunch-editorpackage, which spawns it as a child process. That value is settable through the equally unauthenticatedupdateOptions(). An attacker who can reach the HMR port can therefore chainupdateOptions('behavior', { openInEditor: '<command>' })thenopenInEditor('<any-existing-file>')to execute an arbitrary program on the developer's machine.The HMR port is reachable by a process on the same host, by any peer on the LAN when the dev server is bound with
nuxi dev --host, or by a malicious website the developer visits while the dev server is running (a browser can open the HMR WebSocket cross-origin). Impact is limited to development environments; production builds do not run DevTools.Patches
Fixed in
@nuxt/devtools@3.3.1. Becausenuxtdepends on@nuxt/devtoolsthrough a^3.xrange, updating is a lockfile refresh / reinstall; nonuxtrelease is required.Workarounds
@nuxt/devtoolsto a patched version.nuxi dev --host) on an untrusted network.devtools: { enabled: false }innuxt.config.References
launch-editor: https://www.npmjs.com/package/launch-editorSeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nuxt/devtools (@nuxt/devtools)
v3.3.1Compare Source
No significant changes
View changes on GitHub
v3.2.4Compare Source
🚀 Features
ua-parser-modern- by @antfu (114aa)🐞 Bug Fixes
View changes on GitHub
v3.2.3Compare Source
Bug Fixes
v3.2.2Compare Source
Bug Fixes
Features
promptswith@clack/prompts(#935) (1aa3d2d)v3.2.1Compare Source
Bug Fixes
v3.2.0Compare Source
Bug Fixes
devtools:initializedhook after all modules run (#919) (3662836)Features
3.1.1 (2025-11-25)
Bug Fixes
Features
v3.1.1Compare Source
Bug Fixes
Features
v3.1.0Compare Source
Features
3.0.1 (2025-10-31)
Bug Fixes
Features
v3.0.1Compare Source
Bug Fixes
Features
v3.0.0Compare Source
v2.7.0Compare Source
🐞 Bug Fixes
View changes on GitHub
v2.6.5Compare Source
Bug Fixes
v2.6.4Compare Source
Bug Fixes
textContentinstead ofinnerHtmlfor auth pagechore: update lock (7cadbbe)v2.6.3Compare Source
v2.6.2Compare Source
Bug Fixes
v2.6.1Compare Source
Bug Fixes
@nuxt/schema(#872) (62443ec)v2.6.0Compare Source
Bug Fixes
Features
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.