{"id":"GHSA-x6qj-4h56-5rj5","summary":"@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)","details":"### Summary\nThis is an incomplete fix for [GHSA-6m52-m754-pw2g](https://github.com/nuxt/nuxt/security/advisories/GHSA-6m52-m754-pw2g). Source code may still be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. `nuxt dev --host`) and the developer opens a malicious site on the same network.\n\n### Details\nThe fix for [GHSA-6m52-m754-pw2g](https://github.com/nuxt/nuxt/security/advisories/GHSA-6m52-m754-pw2g) added an `Origin` / `Referer` fallback to the dev-middleware same-origin check, with a `return true` branch when neither header is present so that non-browser clients (curl, the HMR client, address-bar navigation) keep working.\n\nThat fallback is bypassed when a cross-origin attacker request reaches the dev server with all three signal headers absent:\n\n- `Sec-Fetch-Site` is [not sent by browsers to non-potentially-trustworthy destinations](https://w3c.github.io/webappsec-fetch-metadata/#sec-fetch-site-header) (HTTP on a non-loopback address).\n- `Origin` is not sent on non-CORS subresource fetches (a bare `\u003cscript\u003e` with no `crossorigin`).\n- `Referer` can be suppressed by the attacker page with `\u003cmeta name=\"referrer\" content=\"no-referrer\"\u003e` or `referrerpolicy=\"no-referrer\"` on the `\u003cscript\u003e` element.\n\nA classic `\u003cscript src=\"http://VICTIM_LAN_IP:3000/_nuxt/app.js\" referrerpolicy=\"no-referrer\"\u003e` from a non-trustworthy attacker origin produces exactly that header set, the request is allowed, and the attacker page can read the built source out of `window.webpackChunk*` via `Function.prototype.toString()`.\n\nSince the attack requires the dev server to be reachable via a non-potentially-trustworthy origin, only apps using `--host` (or `--host 0.0.0.0`) are affected. Chrome 142+ users are also protected by [Local Network Access restrictions](https://developer.chrome.com/release-notes/142#local_network_access_restrictions).\n\n### PoC\n1. Create a Nuxt project with the webpack / rspack builder.\n1. Run `npm run dev -- --host 0.0.0.0`.\n1. Open `http://localhost:3000` on the developer machine.\n1. From a different LAN host, serve the page below and open it in the same browser.\n1. The compiled module source is exfiltrable from `window.webpackChunknuxt_\u003cprojectname\u003e`.\n\n```html\n\u003c!doctype html\u003e\n\u003cmeta name=\"referrer\" content=\"no-referrer\"\u003e\n\u003cscript\u003e\n  ['/_nuxt/runtime.js', '/_nuxt/app.js'].forEach(p =\u003e {\n    const s = document.createElement('script')\n    s.src = 'http://VICTIM_LAN_IP:3000' + p\n    s.referrerPolicy = 'no-referrer'\n    document.head.appendChild(s)\n  })\n  setTimeout(() =\u003e {\n    const key = Object.keys(window).find(k =\u003e k.startsWith('webpackChunk'))\n    for (const [, mods] of window[key]) {\n      for (const id in mods) {\n        console.log(id, mods[id].toString())\n      }\n    }\n  }, 1500)\n\u003c/script\u003e\n```\n\n### Impact\nUsers using the webpack / rspack builder with `nuxt dev --host` may get the built source code read by malicious websites on the same network, including module identifiers, the developer's local filesystem path, and any developer-controlled strings inlined into the bundle.\n\nThis vulnerability does not affect Chrome 142+ (and other Chromium-based browsers) users due to [Local Network Access restrictions](https://developer.chrome.com/release-notes/142#local_network_access_restrictions).\n\nThe default Vite builder is not affected.\n\n### Patches\nFixed in `@nuxt/webpack-builder@4.4.7` / `@nuxt/rspack-builder@4.4.7` and backported to `@nuxt/webpack-builder@3.21.7` / `@nuxt/rspack-builder@3.21.7` by [#35200](https://github.com/nuxt/nuxt/pull/35200) (4.x: commit [`e351de94`](https://github.com/nuxt/nuxt/commit/e351de943e82db16970618b60dc7fdbaa58630f3); 3.x: commit [`77187ee4`](https://github.com/nuxt/nuxt/commit/77187ee4015e9267fb464951542a3e09e8b5fa05)). The dev-middleware same-origin check now treats a request with no `Sec-Fetch-Site`, no `Origin`, and no `Referer` as same-origin only when the dev server is loopback-bound, closing the header-suppression bypass.\n\nThe fix only ships for the `@nuxt/webpack-builder` and `@nuxt/rspack-builder` packages. The default Vite builder was not affected.\n\n### Workarounds\nIf you cannot upgrade immediately:\n\n- Don't use `nuxt dev --host`. Bind the dev server to `localhost` (the default) and tunnel from other devices via SSH or a reverse proxy that enforces same-origin checks.\n- Use Chrome 142+ or another Chromium-based browser that enforces [Local Network Access restrictions](https://developer.chrome.com/release-notes/142#local_network_access_restrictions).\n- Switch to the Vite builder for development.\n\n### Credit\nReported by Berkan SAL ([@Uhudsavasindankacanokcu2](https://github.com/Uhudsavasindankacanokcu2)) via the Vercel Open Source HackerOne program.\n\nIndependently reported by [@DavidCarliez](https://github.com/DavidCarliez) via GitHub's coordinated disclosure flow (`GHSA-xw96-2f5x-v9pv`), closed as a duplicate of this advisory.","aliases":["CVE-2026-49993"],"modified":"2026-08-24T00:37:00.566998860Z","published":"2026-06-16T23:39:16Z","related":["CVE-2026-49993"],"database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-16T23:39:16Z","nvd_published_at":"2026-06-12T14:16:32Z","cwe_ids":["CWE-749"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-6m52-m754-pw2g"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-x6qj-4h56-5rj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49993"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/pull/35200"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/77187ee4015e9267fb464951542a3e09e8b5fa05"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/e351de943e82db16970618b60dc7fdbaa58630f3"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"}],"affected":[{"package":{"name":"@nuxt/webpack-builder","ecosystem":"npm","purl":"pkg:npm/%40nuxt/webpack-builder"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.4.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x6qj-4h56-5rj5/GHSA-x6qj-4h56-5rj5.json"}},{"package":{"name":"@nuxt/webpack-builder","ecosystem":"npm","purl":"pkg:npm/%40nuxt/webpack-builder"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.15.4"},{"fixed":"3.21.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x6qj-4h56-5rj5/GHSA-x6qj-4h56-5rj5.json"}},{"package":{"name":"@nuxt/rspack-builder","ecosystem":"npm","purl":"pkg:npm/%40nuxt/rspack-builder"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.4.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x6qj-4h56-5rj5/GHSA-x6qj-4h56-5rj5.json"}},{"package":{"name":"@nuxt/rspack-builder","ecosystem":"npm","purl":"pkg:npm/%40nuxt/rspack-builder"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.15.4"},{"fixed":"3.21.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x6qj-4h56-5rj5/GHSA-x6qj-4h56-5rj5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}