{"id":"GHSA-xmq3-q5pm-rp26","summary":"Nuxt DevTools vulnerable to cross-site scripting (XSS)","details":"A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.","aliases":["CVE-2025-52662"],"modified":"2025-11-07T18:12:38.406399Z","published":"2025-11-07T03:30:25Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-11-07T17:41:21Z","nvd_published_at":"2025-11-07T01:15:36Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52662"},{"type":"WEB","url":"https://github.com/nuxt/devtools/commit/7cadbbe9"},{"type":"PACKAGE","url":"https://github.com/nuxt/devtools"},{"type":"WEB","url":"https://github.com/nuxt/devtools/releases/tag/v2.6.4"},{"type":"WEB","url":"https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools"}],"affected":[{"package":{"name":"@nuxt/devtools","ecosystem":"npm","purl":"pkg:npm/%40nuxt/devtools"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-xmq3-q5pm-rp26/GHSA-xmq3-q5pm-rp26.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N"}]}