megachangelog
Security2.6.4

CVE-2025-52662: XSS vulnerability in Nuxt DevTools

A medium-severity security vulnerability in Nuxt DevTools allowed XSS-based authentication token extraction and remote code execution in development environments through improper error message sanitization. The issue has been fixed in version 2.6.4 by rendering error messages as textContent instead of innerHTML.

A medium-severity in Nuxt DevTools was responsibly disclosed, and has been fixed for version 2.6.4. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. security vulnerability

Nuxt DevTools users are encouraged to upgrade to the latest version. Read more details below.

A vulnerability chain in Nuxt DevTools allows remote code execution in development environments through a combination of cross-site scripting (XSS), authentication token exfiltration, and path traversal.

The vulnerability exists in the DevTools authentication page where error messages are rendered without proper sanitization, enabling DOM-based XSS. An attacker can exploit this to steal authentication tokens and leverage a path traversal vulnerability in the WebSocket message handler to write arbitrary files outside the intended directory, leading to remote code execution when configuration files are overwritten.

The XSS was resolved by displaying errors as textContent instead of innterHTML in:

Thanks to @yuske for responsible disclosure.

Read more

Summary

Impact

Resolution

Workarounds

Credit

References

  • Nuxt DevTools 2.6.4

  • Avoid publicly exposing Nuxt DevTools or running Nuxt in production using Dev mode

securityxssdevtoolsnuxtvulnerabilityauth

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →