CVE-2026-71319: Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket v
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71319
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-713190.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71319 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Nuxt is an
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-71321: Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.…nvd · 2026-08-05
- highCVE-2026-71320: Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.…nvd · 2026-08-05
- mediumCVE-2026-71318: Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.…nvd · 2026-08-05
- highCVE-2026-71316: Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime c…nvd · 2026-08-05
- highGHSA-9pgf-384g-p7mv: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body be…ghsa · 2026-08-05
- highGHSA-9473-5f9j-94wq: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Isl…ghsa · 2026-08-05
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07