top of page
perceptive_background_267k.jpg

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returne…

Published:

5 augustus 2026 om 00:00:00

Alert date:

6 augustus 2026 om 01:01:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A vulnerability in the Nuxt open-source Vue.js web framework (versions 4.4.0 to 4.5.1) allows runtime cache entries for payload JSON files to be returned before route middleware and page guards are enforced. This occurs because import.meta.prerender is not properly enforced, leading to potential disclosure of another user's server-side rendering (SSR) data. The flaw could expose sensitive user information across sessions in affected deployments. The issue has been assigned CVE-2026-71316 and is classified as an information disclosure vulnerability. A fix was released in Nuxt version 4.5.1. Users running affected versions are advised to upgrade immediately to mitigate the risk of cross-user data leakage.

Technical details

Mitigation steps:

Affected products:

Nuxt 4.4.0
Nuxt 4.5.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page