---
title: "Nuxt security vulnerabilities: what Netlify users need to know"
description: "The Nuxt team has disclosed several vulnerabilities fixed in Nuxt 4.5.1 and 3.21.10. Affected Netlify projects should upgrade."
source: "https://www.netlify.com/changelog/2026-07-27-nuxt-security-vulnerabilities/"
last_updated: "2026-07-27T19:51:27.000Z"
---
The Nuxt team has disclosed [several security vulnerabilities](https://github.com/nuxt/nuxt/security/advisories) fixed in Nuxt 4.5.1 and 3.21.10, ranging from a high-severity server-side remote code execution (under specific conditions) to lower-severity and development-only issues. Here’s what Netlify customers need to know.

## Vulnerabilities

-   [**GHSA-9473-5f9j-94wq**](https://github.com/nuxt/nuxt/security/advisories/GHSA-9473-5f9j-94wq) (High): remote code execution via [server island](https://nuxt.com/docs/4.x/api/components/nuxt-island) props
-   [**GHSA-48hr-524c-v5w3**](https://github.com/nuxt/nuxt/security/advisories/GHSA-48hr-524c-v5w3) (Medium): unauthorized component instantiation via server island props
-   [**GHSA-hxvh-4h3w-prp9**](https://github.com/nuxt/nuxt/security/advisories/GHSA-hxvh-4h3w-prp9) (High): route rule authorization bypass when a route rule key contains an uppercase character
-   [**GHSA-hxcr-hm88-mpq6**](https://github.com/nuxt/nuxt/security/advisories/GHSA-hxcr-hm88-mpq6) and [**GHSA-9pgf-384g-p7mv**](https://github.com/nuxt/nuxt/security/advisories/GHSA-9pgf-384g-p7mv) (High): server component denial of service
-   [**GHSA-wm8w-6qjm-cv43**](https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43) (High): cross-user disclosure of cached payloads (Nuxt 4.x only, 4.4.0 and later)
-   [**GHSA-7c4v-fwgw-9rf7**](https://github.com/nuxt/nuxt/security/advisories/GHSA-7c4v-fwgw-9rf7) (Low): dev server path disclosure
-   [**GHSA-279x-mwfv-vcqv**](https://github.com/nuxt/nuxt/security/advisories/GHSA-279x-mwfv-vcqv) (Critical, development only): remote code execution in Nuxt DevTools, fixed in `@nuxt/devtools@3.3.1`

## Impact on Netlify

### Remote code execution (GHSA-9473-5f9j-94wq)

This issue **only applies under uncommon conditions**: it requires Vue’s runtime compiler (`vue.runtimeCompiler: true`, which is off by default) and a server island that forwards untrusted input into a component. Few applications meet both conditions, so real-world exposure is limited. We’ve proactively reached out to the very small number of Netlify customers whose projects could potentially be affected.

### Route rule authorization bypass (GHSA-hxvh-4h3w-prp9)

This is a framework-level issue that affects Nuxt apps **regardless of hosting provider**. It is not specific to Netlify. **You’re affected if you use `routeRules` with `appMiddleware` as an authorization gate and any rule key contains an uppercase character**, such as a rule derived from a page like `pages/Admin.vue` or written explicitly as `routeRules: { '/Admin': ... }`. Because routing is case-insensitive by default, the page was served while its route rule (and the middleware guarding it) was silently skipped. This is a regression in the earlier fix for [CVE-2026-53721](https://github.com/nuxt/nuxt/security/advisories/GHSA-mm7m-92g8-7m47), so upgrading only to 4.4.7 or 3.21.7 does not protect you. Upgrade to Nuxt 4.5.1 or 3.21.10, then audit any uppercase route rule keys used for access control.

### Denial of service (GHSA-hxcr-hm88-mpq6, GHSA-9pgf-384g-p7mv)

These are server-side denial-of-service (DoS) vulnerabilities. **On Netlify, these have minimal impact**: our autoscaling serverless architecture means that a malicious request resulting in a crashed or hung function does not affect other requests. However, active exploitation could increase your function costs.

### Cross-user payload disclosure (GHSA-wm8w-6qjm-cv43)

If you use the `cache`, `swr`, or `isr` route rules on authenticated pages that render user-specific data, a cached payload could be served to the wrong user. **After upgrading, purge any upstream CDN cache (e.g. Akamai or Cloudflare) that may already be holding a leaked payload.** Upgrading alone won’t evict it.

### Development-only issues (GHSA-279x-mwfv-vcqv, GHSA-7c4v-fwgw-9rf7)

The Nuxt DevTools remote code execution and the dev server path disclosure **only affect local development**, not deployed Netlify sites. Still, refresh your lockfile so it picks up `@nuxt/devtools@3.3.1`.

## What should I do?

We strongly recommend upgrading as soon as possible to a patched release:

-   `nuxt` 4.5.1 or later (for Nuxt 4)
-   `nuxt` 3.21.10 or later (for Nuxt 3)

Running `npx nuxt upgrade --dedupe` also refreshes your lockfile so it pulls in `@nuxt/devtools@3.3.1`, which fixes the critical development-only issue above.

Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are [automatically deleted](https://docs.netlify.com/deploy/manage-deploys/manage-deploys-overview/#automatic-deploy-deletion). Consider [deleting these deploys manually](https://docs.netlify.com/deploy/manage-deploys/manage-deploys-overview/#manual-deploy-deletion-through-the-netlify-ui).

## Resources

-   [Nuxt security post](https://nuxt.com/blog/v4-5-security)
-   [Nuxt security advisories](https://github.com/nuxt/nuxt/security/advisories)