CVE-2025-24361

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24361
Aliases
Published
2025-01-25T01:15:24Z
Modified
2025-01-26T00:59:07.146981Z
Summary
[none]
Details

Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0.0 through 3.15.12 of the webpack builder or version 3.12.2 through 3.152 of the rspack builder and a victim opens a malicious web site. Because the request for classic script by a script tag is not subject to same origin policy, an attacker can inject a malicious script in their site and run the script. By using Function::toString against the values in window.webpackChunknuxt_app, the attacker can get the source code. Version 3.15.13 of Nuxt patches this issue.

References

Affected packages

Git / github.com/nuxt/nuxt

Affected ranges

Type
GIT
Repo
https://github.com/nuxt/nuxt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

3.*

3.1.1

@nuxt/ui-assets@0.*

@nuxt/ui-assets@0.1.0
@nuxt/ui-assets@0.2.0
@nuxt/ui-assets@0.2.1

@nuxt/ui-templates@0.*

@nuxt/ui-templates@0.1.0
@nuxt/ui-templates@0.1.1
@nuxt/ui-templates@0.2.0
@nuxt/ui-templates@0.2.1
@nuxt/ui-templates@0.2.2
@nuxt/ui-templates@0.3.0
@nuxt/ui-templates@0.3.1
@nuxt/ui-templates@0.3.2
@nuxt/ui-templates@0.3.3
@nuxt/ui-templates@0.4.0

@nuxt/ui-templates@1.*

@nuxt/ui-templates@1.1.0
@nuxt/ui-templates@1.1.1
@nuxt/ui-templates@1.2.0
@nuxt/ui-templates@1.2.1
@nuxt/ui-templates@1.3.0
@nuxt/ui-templates@1.3.1
@nuxt/ui-templates@1.3.2
@nuxt/ui-templates@1.3.3

@nuxt/ui@0.*

@nuxt/ui@0.1.0
@nuxt/ui@0.1.1
@nuxt/ui@0.2.0
@nuxt/ui@0.3.0
@nuxt/ui@0.3.1
@nuxt/ui@0.3.2
@nuxt/ui@0.3.3
@nuxt/ui@0.4.0
@nuxt/ui@0.4.1

v3.*

v3.0.0
v3.0.0-rc.1
v3.0.0-rc.10
v3.0.0-rc.11
v3.0.0-rc.12
v3.0.0-rc.13
v3.0.0-rc.14
v3.0.0-rc.2
v3.0.0-rc.3
v3.0.0-rc.4
v3.0.0-rc.5
v3.0.0-rc.6
v3.0.0-rc.7
v3.0.0-rc.8
v3.0.0-rc.9
v3.1.0
v3.1.1
v3.1.2
v3.10.0
v3.10.1
v3.10.2
v3.10.3
v3.11.0
v3.11.1
v3.11.2
v3.12.0
v3.12.1
v3.12.2
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.6.4
v3.6.5
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.7.4
v3.8.0
v3.8.1
v3.8.2
v3.9.0
v3.9.1
v3.9.2
v3.9.3