https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt
, nuxtlabs
and nuxt-themes
GitHub organizations. A patch in version 1.6.2 fixed the issue.
{ "github_reviewed_at": "2023-04-21T20:26:07Z", "cwe_ids": [ "CWE-798" ], "nvd_published_at": "2023-04-18T01:15:07Z", "severity": "CRITICAL", "github_reviewed": true }