{"id":"GHSA-279x-mwfv-vcqv","summary":"Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host","details":"### Impact\n\nNuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://\u003chost\u003e:\u003cport\u003e/`, subprotocol `vite-hmr`) can call RPC methods, with no token, handshake, or origin check before the channel is established. The `updateOptions()`, `clearOptions()`, and `openInEditor()` methods do not enforce the `ensureDevAuthToken` check that the other mutating methods use.\n\n`openInEditor()` reads the persisted `behavior.openInEditor` value and passes it to the `launch-editor` package, which spawns it as a child process. That value is settable through the equally unauthenticated `updateOptions()`. An attacker who can reach the HMR port can therefore chain `updateOptions('behavior', { openInEditor: '\u003ccommand\u003e' })` then `openInEditor('\u003cany-existing-file\u003e')` to execute an arbitrary program on the developer's machine.\n\nThe HMR port is reachable by a process on the same host, by any peer on the LAN when the dev server is bound with `nuxi dev --host`, or by a malicious website the developer visits while the dev server is running (a browser can open the HMR WebSocket cross-origin). Impact is limited to development environments; production builds do not run DevTools.\n\n### Patches\n\nFixed in `@nuxt/devtools@3.3.1`. Because `nuxt` depends on `@nuxt/devtools` through a `^3.x` range, updating is a lockfile refresh / reinstall; no `nuxt` release is required.\n\n### Workarounds\n\n- Update `@nuxt/devtools` to a patched version.\n- Do not run the dev server bound to a non-loopback interface (`nuxi dev --host`) on an untrusted network.\n- Disable DevTools entirely with `devtools: { enabled: false }` in `nuxt.config`.\n\n### References\n\n- GHSA-279x-mwfv-vcqv\n- `launch-editor`: https://www.npmjs.com/package/launch-editor","aliases":["CVE-2026-71319"],"modified":"2026-08-20T05:15:41.117942772Z","published":"2026-08-05T21:27:39Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-306","CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-08-05T21:27:39Z"},"references":[{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-279x-mwfv-vcqv"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"}],"affected":[{"package":{"name":"@nuxt/devtools","ecosystem":"npm","purl":"pkg:npm/%40nuxt/devtools"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-279x-mwfv-vcqv/GHSA-279x-mwfv-vcqv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}