Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json). The endpoint's local-request gate (isLocalDevRequest) is header-based and trusts the attacker-supplied Host header rather than the connected peer address. When the dev server is bound to a network-reachable interface (e.g. nuxt dev --host) and experimental.chromeDevtoolsProjectSettings is enabled (the default), an unauthenticated attacker on the LAN can send a request with a spoofed Host header and no browser-specific headers (Sec-Fetch-Site, Origin, Referer) to retrieve the project's absolute filesystem root path (rootDir) and a persistent per-project workspace UUID. Production builds are unaffected. Fixed in 4.5.1 and 3.21.10. | |
| Title | Nuxt before 4.5.1 Information Disclosure via Chrome DevTools | |
| First Time appeared |
Nuxt
Nuxt nuxt\/rspack-builder |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:nuxt:nuxt\/rspack-builder:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nuxt
Nuxt nuxt\/rspack-builder |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T17:50:47.713Z
Reserved: 2026-08-10T13:53:42.482Z
Link: CVE-2026-72744
Updated: 2026-08-11T17:41:07.999Z
Status : Received
Published: 2026-08-11T13:19:05.210
Modified: 2026-08-11T18:18:23.890
Link: CVE-2026-72744
No data.
OpenCVE Enrichment
No data.