Nuxt · @Nuxt/Webpack-Builder · CVE-2026-49993
**Name of the Vulnerable Software and Affected Versions**
@nuxt/rspack-builder versions 3.15.4 through 3.21.6
@nuxt/rspack-builder versions 4.0.0 through 4.4.6
@nuxt/webpack-builder versions 3.15.4 through 3.21.6
@nuxt/webpack-builder versions 4.0.0 through 4.4.6
**Description**
An incomplete fix in the webpack and rspack builders allows source code to be stolen during development. This occurs if the development server is bound to a non-loopback address, such as when using the `nuxt dev --host` command, and a developer visits a malicious website on the same network.
**Recommendations**
Update versions 3.15.4 through 3.21.6 to 3.21.7.
Update versions 4.0.0 through 4.4.6 to 4.4.7.