A critical vulnerability in Nuxt DevTools (CVE-2026-71319) allows attackers to execute arbitrary commands on developer machines, with a CVSS score of 9.6. This issue affects versions prior to 3.3.1 and is primarily relevant during development mode. The vulnerability arises from an unauthenticated RPC channel exposed by the DevTools, enabling remote code execution. No exploitation has been confirmed yet. Users are advised to update to version 3.3.1 to mitigate risks.
Critical Nuxt DevTools flaw lets hackers run code on dev machines
CyberSIXT Evidence Panel
Article by CyberSIXT