What is CVE-2026-71319?
In Nuxt versions prior to 3.3.1, the Nuxt DevTools RPC channel over Vite HMR WebSocket lacks authentication, allowing any client with network access to perform remote code execution in development mode. Affected users must upgrade immediately to the latest version and ensure development servers are only exposed on trusted networks.
Azərbaycanca: Nuxt veb inkişaf framework-unun 3.3.1-dən əvvəlki versiyalarında, Nuxt DevTools-un yalnız development rejimində istifadə olunan RPC kanalı üzərində autentifikasiyanın olmaması səbəbindən, Vite HMR WebSocket-ə çıxışı olan istənilən şəxs remote code execution həyata keçirə bilər. Təsirə məruz qalan istifadəçilər dərhal Nuxt-u ən son versiyaya yeniləməli və development server-lərini yalnız etibarlı şəbəkələrdə işə salmalıdır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of Nuxt are affected by CVE-2026-71319?
Nuxt versions prior to 3.3.1 are affected.
What does an attacker need to exploit this vulnerability?
The attacker only needs network access to the Vite HMR WebSocket.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.