megachangelog
SecurityJuly 2026

Nuxt July 2026 security advisory

Nuxt released versions 4.5.1, 3.21.10, and DevTools 3.3.1 to address eight security vulnerabilities including a high-severity server-side remote code execution flaw. Vercel deployed WAF mitigations platform-wide before public disclosure, automatically protecting deployed applications, but users must still upgrade to patched versions for complete protection.

The team has released Nuxt 4.5.1 and 3.21.10, along with 3.3.1, to address eight security advisories, including a high-severity server-side remote code execution vulnerability.Nuxt@nuxt/devtools

Vercel received advance notice of the server-side remote code execution vulnerability, , and deployed platform-wide WAF mitigations before public disclosure.GHSA-9473-5f9j-94wq

Applications deployed on Vercel are automatically protected by these mitigations, with no configuration changes required. However, do not rely on them for full protection. Upgrading to a patched version is still required.

The WAF mitigations cover only direct exploitation of the server-side RCE. The remaining component-instantiation, caching, authorization, denial-of-service, and development-time vulnerabilities require upgrading Nuxt and Nuxt DevTools.

All Nuxt users should upgrade as soon as possible:

To upgrade, run:

This also refreshes the lockfile, pulling in the patched Nuxt DevTools version.

Users who previously upgraded for the earlier route rule advisory, CVE-2026-53721, must still upgrade. The newly disclosed authorization bypass is a regression in that earlier fix.

Nuxt 4 users who cache authenticated pages containing user-specific data should also follow Nuxt’s guidance and purge any upstream caches that may still contain payloads generated before the fix.

Vercel platform protections provide an additional layer of defense, but they are not a replacement for upgrading affected dependencies.

Read the for affected configurations and complete remediation guidance.Nuxt security announcement

Read more

Vulnerabilities addressed

Vercel platform protections

Recommended action

Vulnerability

Severity

Advisory

Server-side remote code execution via server island props

High

GHSA-9473-5f9j-94wq

Unauthorized component instantiation via server island props

Medium

GHSA-48hr-524c-v5w3

Route rule authorization bypass

High

GHSA-hxvh-4h3w-prp9

Server component denial of service

High

, GHSA-hxcr-hm88-mpq6GHSA-9pgf-384g-p7mv

Cross-user disclosure of cached payloads, affecting Nuxt 4.x versions 4.4.0 and later

High

GHSA-wm8w-6qjm-cv43

Development server path disclosure

Low

GHSA-7c4v-fwgw-9rf7

Remote code execution in Nuxt DevTools, development-only, fixed in 3.3.1@nuxt/devtools

Critical

GHSA-279x-mwfv-vcqv

  • Nuxt 4: or later4.5.1

  • Nuxt 3: or later3.21.10

  • Nuxt DevTools: or later3.3.1

securitynuxtrcevulnerabilitydevtools

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →