PT-2025-45798 · Npm · Nuxt Devtools

Published

2025-11-07

·

Updated

2025-11-07

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N
A vulnerability in Nuxt DevTools has been fixed in version 2.6.4*. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-XMQ3-Q5PM-RP26

Affected Products

Nuxt Devtools