{"id":"CVE-2026-53721","aliases":["GHSA-mm7m-92g8-7m47"],"title":"Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher","summary":"Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher","severity":"high","cwe":["CWE-178","CWE-863"],"vendor":"nuxt","product":"nuxt","ecosystem":"npm","affected":["nuxt >= 4.0.0, < 4.4.7","nuxt >= 3.11.0, < 3.21.7"],"patched":["nuxt 4.4.7","nuxt 3.21.7"],"published":"2026-06-16","updated":"2026-06-16","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mm7m-92g8-7m47","references":[{"url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-mm7m-92g8-7m47"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53721"},{"url":"https://github.com/nuxt/nuxt/commit/07e39cd6f26e407b4192b7865bd17bc44536b9bb"},{"url":"https://github.com/nuxt/nuxt/commit/3f3e3fa7b5eec8e495f4f8ce0a54813a8875a11e"},{"url":"https://github.com/advisories/GHSA-mm7m-92g8-7m47"}],"tags":["ghsa","npm"],"epss":0.00512,"epssPercentile":0.41074,"ingestedAt":"2026-07-07T15:41:58.382Z","slug":"CVE-2026-53721","body":"## Overview\n\n## Impact\n\nNuxt looks up `routeRules` for the current navigation by calling\n`getRouteRules({ path: to.path })` from the page-router plugin and the\nno-pages router plugin. The compiled `routeRules` matcher (built on\n`rou3`) performs case-sensitive matching, while vue-router is configured\nwith its default `sensitive: false` and matches paths case-insensitively.\n\nThe two routers therefore disagree on which rules apply to a given\nrequest path: vue-router still matches the page record for\n`/Admin/dashboard`, but the `routeRules` lookup for the same path\nreturns no match. Any `appMiddleware` declared via `routeRules` is never\nadded to the middleware set and never runs, on both SSR and client\nnavigations. The same path skips other path-keyed route rules in the\nsame way (`ssr`, `redirect`, `appLayout`, and the prerender / payload\nhints used client-side).\n\nFor applications using `routeRules` with `appMiddleware` as an\nauthorization gate (a documented pattern), an attacker can flip the case\nof any static segment in a protected URL (for example `/Admin/dashboard`\ninstead of `/admin/dashboard`) to render the protected page with the\nmiddleware skipped. The server returns the fully server-rendered page\nincluding any `useFetch` / `useAsyncData` results captured during SSR.\n\nThis is an instance of CWE-178 (Improper Handling of Case Sensitivity)\nleading to CWE-863 (Incorrect Authorization) for apps that treat\n`appMiddleware` as an authorization boundary.\n\n## Mitigating factors\n\n- Only affects apps that use `routeRules.appMiddleware`. The more\n  idiomatic `definePageMeta({ middleware })` is bound to the matched\n  route record and is unaffected.\n- Nuxt route middleware is documented as an app-layer concern, not a\n  server-side auth boundary; well-built apps enforce authorization\n  again at the API / data-fetching layer.\n- Apps that explicitly set `router.options.sensitive = true` are not\n  affected.\n\n## Patches\n\nFixed in `nuxt@4.4.7` (commit [`07e39cd6`](https://github.com/nuxt/nuxt/commit/07e39cd6f26e407b4192b7865bd17bc44536b9bb)) and backported to `nuxt@3.21.7` (commit [`3f3e3fa7`](https://github.com/nuxt/nuxt/commit/3f3e3fa7b5eec8e495f4f8ce0a54813a8875a11e)). The fix normalizes the path used for `routeRules` lookups so it matches vue-router's default case-insensitive semantics.\n\n## Workarounds\n\nUntil you can upgrade, you can mitigate by either:\n\n1. Setting `router.options.sensitive = true` so vue-router matches\n   case-sensitively (this changes route-matching behaviour app-wide).\n2. Moving security-critical middleware off `routeRules.appMiddleware`\n   and onto `definePageMeta({ middleware: [...] })` on the protected\n   page components, which is bound to the matched record.\n3. Enforcing authorization at the API / data-fetching layer (which you\n   should be doing in any case).\n\n## Credit\n\nReported by Anthropic / Claude through Anthropic's coordinated\nvulnerability disclosure process. Reference: ANT-2026-9FSEBYMC.\n\n## Affected packages\n\n- `nuxt >= 4.0.0, < 4.4.7`\n- `nuxt >= 3.11.0, < 3.21.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nuxt 4.4.7`\n- `nuxt 3.21.7`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}