GHSA-2x6f-57hp-86fxMedium· 5.5▾ SunlitDuplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-534h-c3cw-v3h9. This link is maintained to preserve external references.
Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and connect. Unprivileged co-resident users can exploit the unprotected module request handler to read arbitrary files such as .env and SSH keys through the SSR plugin pipeline. Production builds are unaffected, as the IPC server runs only in development.
nuxt >= 4.0.0, < 4.4.7Upgrade to a patched release:
nuxt 4.4.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56301Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
GHSA-534h-c3cw-v3h9Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
GHSA-xppm-jmw6-fhmfLowDuplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-56317LowCross-site scripting via <NoScript> slot content in Nuxt's head components
GHSA-4jjw-pwvw-q6w3Medium· 6.2Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-7c4v-fwgw-9rf7MediumNuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint