{"slug": "socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities", "title": "Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities", "summary": "Socket has released free Certified Patches for two high-severity Nuxt vulnerabilities, including a server-side remote code execution flaw (GHSA-9473-5f9j-94wq) that can be exploited through server island props. Nuxt 4.5.1 and 3.21.10 address eight GitHub Security Advisories across Nuxt and Nuxt DevTools, with a critical remote code execution bug in @nuxt/devtools 3.3.1 fixed separately. Socket's patches allow teams to remediate issues without waiting for a full dependency upgrade.", "body_md": "Security News\n\n[The AI Industry Is Betting on Open Weights](/blog/the-ai-industry-is-betting-on-open-weights)\n\nAn open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.\n\nSocket releases free Certified Patches for high-severity Nuxt vulnerabilities, including server-side remote code execution through server island props.\n\nJuly 27, 2026\n\n3 min read\n\nNuxt has released [security updates](https://nuxt.com/blog/v4-5-security) for multiple vulnerabilities affecting Nuxt 3.x and 4.x, along with a separate critical development-only vulnerability in `@nuxt/devtools`\n\n.\n\nNuxt 4.5.1 and 3.21.10 address issues including server-side remote code execution, authorization bypass, denial of service, and cross-user payload disclosure. `@nuxt/devtools`\n\n3.3.1 fixes a critical remote code execution vulnerability affecting development servers.\n\nSocket has published Certified Patches for two of the disclosed Nuxt advisories and is preparing patches for the remaining issues. Certified Patches for Critical and High severity vulnerabilities are free to use, including for teams that are not Socket customers.\n\nThe Nuxt release addresses eight GitHub Security Advisories across Nuxt and Nuxt DevTools.\n\nThe most serious production issue, [GHSA-9473-5f9j-94wq](https://socket.dev/vuln/ghsa/GHSA-9473-5f9j-94wq), can enable server-side remote code execution through server island props. It requires `vue.runtimeCompiler`\n\nto be enabled, which is off by default, along with an application pattern where attacker-controlled island props reach Vue’s dynamic component resolution.\n\nA related vulnerability, [GHSA-48hr-524c-v5w3](https://socket.dev/vuln/ghsa/GHSA-48hr-524c-v5w3), can allow unauthorized instantiation of HTML elements or globally registered components through server island props. It does not enable code execution, but it can affect applications using polymorphic component patterns or Vue attribute fallthrough.\n\nOther fixes address:\n\n`appMiddleware`\n\nis used with route rules containing uppercase characters`nuxt dev`\n\nwith DevTools enabledThe DevTools issue affects development environments, not production deployments. It can be reached by another process on the host, users on the local network when the dev server is exposed with `--host`\n\n, or a malicious site visited while the dev server is running.\n\nNuxt recommends upgrading to Nuxt 4.5.1 or 3.21.10:\n\n```\nnpx nuxt upgrade --dedupe\n```\n\nRefresh your lockfile as part of the upgrade to ensure it resolves `@nuxt/devtools@3.3.1`\n\nor later.\n\nTeams using authenticated pages with Nuxt `cache`\n\n, `swr`\n\n, or `isr`\n\nroute rules should also purge CDN and edge caches after upgrading. Previously cached `_payload.json`\n\nresponses may remain available until explicitly evicted.\n\nSocket has published a free Certified Patch for [GHSA-9473-5f9j-94wq](https://socket.dev/vuln/ghsa/GHSA-9473-5f9j-94wq), the high-severity server-side remote code execution issue involving server island props.\n\nApply it with:\n\n```\nsocket patch add GHSA-9473-5f9j-94wq\n```\n\nYou can also view the Certified Patch for an affected version [here](https://socket.dev/patches/101df885-3b96-4e2f-ba95-a7f77b12878b).\n\nSocket has also published a Certified Patch for [GHSA-48hr-524c-v5w3](https://socket.dev/vuln/ghsa/GHSA-48hr-524c-v5w3), which addresses unauthorized component instantiation through server island props:\n\n```\nsocket patch add GHSA-48hr-524c-v5w3\n```\n\nA patch for an affected version is available [here](https://socket.dev/patches/dffcb2c5-b22f-4442-a83d-22f3adbd9df8).\n\nCertified Patches apply a minimal, reviewed change directly to vulnerable package versions while preserving the rest of the package’s behavior. They allow teams to remediate an issue without waiting on a full dependency upgrade or dependency-tree refactor.\n\nWe are preparing Certified Patches for the remaining Nuxt advisories and will update this post as they are completed. Once all patches are available, Socket’s merged patches will provide a consolidated way to remediate the full set of disclosed Nuxt vulnerabilities.\n\nOrganizations using Nuxt should:\n\n`@nuxt/devtools`\n\nto 3.3.1 or later and refresh lockfiles.`cache`\n\n, `swr`\n\n, or `isr`\n\nroute rules.`appMiddleware`\n\nprotects routes whose route-rule keys include uppercase characters.Subscribe to our newsletter\n\nGet notified when we publish new security blog posts!\n\nSecurity News\n\nAn open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.\n\nSecurity News\n\n/Research\n\nA fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.\n\nResearch\n\n/Security News\n\nA large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.", "url": "https://wpnews.pro/news/socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities", "canonical_source": "https://socket.dev/blog/patches-for-nuxt-security-vulnerabilities?utm_medium=feed", "published_at": "2026-07-27 22:57:36+00:00", "updated_at": "2026-07-27 23:38:40.725471+00:00", "lang": "en", "topics": ["developer-tools", "ai-tools"], "entities": ["Socket", "Nuxt", "GitHub", "GHSA-9473-5f9j-94wq", "GHSA-48hr-524c-v5w3", "@nuxt/devtools"], "alternates": {"html": "https://wpnews.pro/news/socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities", "markdown": "https://wpnews.pro/news/socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities.md", "text": "https://wpnews.pro/news/socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities.txt", "jsonld": "https://wpnews.pro/news/socket-releases-free-certified-patches-for-nuxt-security-vulnerabilities.jsonld"}}