Nuxt July 2026 security advisory
Executive Take
Any engineering leader running Nuxt in production needs a patch cycle this week, not next sprint, since one of the eight flaws is a regression of a previously "fixed" authorization bug and platform-level WAF coverage only blocks one of the eight issues.
Executive Summary
Nuxt released versions 4.5.1, 3.21.10, and DevTools 3.3.1 to fix eight vulnerabilities, including a high-severity server-side remote code execution flaw (GHSA-9473-5f9j-94wq) and a critical Nuxt DevTools RCE (GHSA-279x-mwfv-vcqv). Vercel deployed WAF mitigations pre-disclosure for Vercel-hosted apps but says upgrading remains mandatory.
Why It Matters
Technology and cybersecurity leaders using Nuxt/Vue for customer-facing apps face real exposure to RCE and cross-user data leakage until they patch, regardless of hosting provider mitigations. GCC and enterprise technology teams running shared infrastructure should treat the cache-purge guidance for authenticated pages as urgent, not optional.