securityonline.info 8/12/2026, 3:19:36 PM · external

Critical Nuxt DevTools flaw lets hackers run code on dev machines

Critical Nuxt DevTools flaw lets hackers run code on dev machines
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Nuxt DevTools (CVE-2026-71319) allows attackers to execute arbitrary commands on developer machines, with a CVSS score of 9.6. This issue affects versions prior to 3.3.1 and is primarily relevant during development mode. The vulnerability arises from an unauthenticated RPC channel exposed by the DevTools, enabling remote code execution. No exploitation has been confirmed yet. Users are advised to update to version 3.3.1 to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT