CVE-2026-71319 with a CVSS score of 9.6 is a vulnerability affecting @nuxt/devtools. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`) can call RPC methods, with no in the @nuxt/devtools plugin that allows an attacker to execute arbitrary commands on the developer's host via the unauthenticated Nuxt DevTools RPC channel exposed by Vite HMR WebSocket, impacting development environments only; affected versions include all prior to 3.3.1, which can be exploited by chaining updateOptions and openInEditor methods to run a malicious program on the host, with the impact limited to development environments as production builds do not run DevTools.
We recommend you to update @nuxt/devtools to version 3.3.1.[/subscribe_to_unlock_form]
CVE-2026-71319 with a CVSS score of 9.6 is a vulnerability affecting @nuxt/devtools. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`) can call RPC methods, with no in the @nuxt/devtools plugin that allows an attacker to execute arbitrary commands on the developer's host via the unauthenticated Nuxt DevTools RPC channel exposed by Vite HMR WebSocket, impacting development environments only; affected versions include all prior to 3.3.1, which can be exploited by chaining updateOptions and openInEditor methods to run a malicious program on the host, with the impact limited to development environments as production builds do not run DevTools.
We recommend you to update @nuxt/devtools to version 3.3.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]