What is CVE-2026-72744?
CVE-2026-72744 is an information disclosure vulnerability in the Nuxt development server's Chrome DevTools workspace endpoint, affecting versions >=4.4.7 and <4.5.1, and >=3.21.7 and <3.21.10. It stems from an insufficient header-based local request check (isLocalDevRequest), potentially exposing sensitive data. Users should immediately update to the patched versions.
Azərbaycanca: CVE-2026-72744 Nuxt framework-ünün development serverində Chrome DevTools workspace endpoint-i vasitəsilə informasiya sızması zəifliyidir. Bu, 4.4.7 ilə 4.5.1 və 3.21.7 ilə 3.21.10 versiya aralıqlarına təsir edir, başlıq əsaslı yerli sorğu yoxlamasının (isLocalDevRequest) yetərsiz olması səbəbindən baş verir. İstifadəçilərə təsirlənmiş versiyaları dərhal yamaqlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which software component does CVE-2026-72744 affect?
The vulnerability affects the Chrome DevTools workspace endpoint on the Nuxt development server.
What is the root cause of CVE-2026-72744?
The information disclosure stems from an insufficient header-based local request check (isLocalDevRequest).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.