Security · 19h ago
Nuxt Patches High-Severity RCE and Other Flaws in Urgent Update
Nuxt released versions 4.5.1 and 3.21.10 to fix eight security issues, including a high-severity server-side remote code execution vulnerability. A critical RCE in Nuxt DevTools was also patched. Vercel deployed WAF mitigations for the server-side RCE but urges all users to upgrade immediately.
Meridian48 take
While Vercel's WAF provides some cover, the breadth of vulnerabilities—including an authorization bypass regression—means upgrading is non-negotiable for any production Nuxt site.
nuxtsecurity-advisory