CVE-2026-71319Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-06); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-06: 2Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-06: 2Technical Details · 2026-08-12: 108-0608-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-062
Disclosure2
2026-08-121
Patch1
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now. #Nuxt #VueJS #CVE #RCE #CyberSecurity http://securityonline.info/nuxt-devtools-vulnerability/

    Post summary

    The post announces CVE-2026-71319, highlights its high severity and the ability to run arbitrary commands, and states that a patch is now available.

    020112883
    13.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-71319 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite H… https://www.cve.org/CVERecord?id=CVE-2026-71319

    Post summary

    A new CVE (CVE-2026-71319) affecting Nuxt’s DevTools before v3.3.1 has been disclosed, detailing an unintended bidirectional RPC channel in development mode, with no PoC, exploit, patch, or active exploitation reports.

    01011803
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-71319 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite H… https://www.cve.org/CVERecord?id=CVE-2026-71319 ----- Traducción: CVE-2026-71319 Nux… http://infoflow.cloud`

    Post summary

    A brief tweet discloses CVE-2026-71319, noting that Nuxt DevTools in development mode exposes a bidirectional RPC channel, but it provides no PoC, exploit, patch, or evidence of active use.

    0000053
    97 followersView on X

Explore more