⚠️ This is a security release. We recommend upgrading as soon as possible with
npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
🩹 Fixes
- nuxt: Clear hide/reset timeouts in set() (#35534)
- nuxt: Preserve trailing slash in NuxtLink href when unset (#35501)
- vite: Resolve SSR inlined CSS module class name mismatch (#35610)
- nuxt: Sync layout meta during middleware on SSR (#35633)
- nuxt: Update client URL to match SSR on fatal middleware error (#35637)
- nuxt: Watch external component directories in development (#35652)
- nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#35656)
- nuxt: Return global route for
useRoutein detached effect scope (#35659) - nuxt: Ignore custom
nameorpathwhen reusing an existing page inpages:extend(#35661) - nuxt: Preserve explicit
useFetchmethod inference (#35671) - nuxt: Correct default export detection in plugin metadata (#35676)
- nuxt: Reload real page module on HMR of JSX render-function pages (#35678)
- vite: Ensure server sourcemap-preserver plugin actually runs (#35680)
- nuxt: Resolve
@unhead/vue/*from nuxt's dependency tree (#35690) - nuxt: Don't apply scroll behaviour after a subsequent nav (#35719)
- vite: Preserve css suffix when extracting ssr inline styles (#35714)
- nuxt: Don't exclude client entry module from style extraction (#35720)
- kit: Avoid mutating layer configs when resolving options (#35729)
- nuxt: Generate layout types even when pages module is disabled (#35717)
- nitro: Skip resource hints for stylesheets already rendered as blocking links (#35691)
- nuxt: Revalidate cached route payloads instead of using
force-cache(#35672) - nuxt: Preserve query params in cached payload extraction (#35696)
- rspack,webpack: Resolve loaders and runtime deps from nuxt dirs (#35568)
- nuxt: Render client components in nested server components (#35669)
- nuxt: Remove dev error overlay when error is cleared (#35821)
- rspack,webpack: Resolve bundled postcss defaults from builder (#35823)
- schema: Normalise slashes in
app.buildAssetsDir(#35833) - nuxt: Case-fold route rule keys to match folded lookups (619963309)
- nitro: Require loopback peer for chrome devtools workspace endpoint (00f71bb65)
- nitro: Bound island props and v-for to prevent unauthenticated DoS (668cdfdfd)
- nuxt: Reject reserved
templateisland prop under runtime compiler (5b60017f7) - nuxt: Reject top-level
asprop for islands (00a2b0494)
📖 Documentation
- Document relative baseURL workarounds (#34004)
- Warn about
runtimeCompilersecurity best practices (b76c1a8bd) - Warn about validating server component props (f6d72628d)
✅ Tests
- Guard against transient undefined
_routein gotoPath (5391e7e6a) - Raise route-HMR polling timeout to reduce e2e flakiness (cbc757c63)
- kit: Scope loadNuxt temp dir so it doesn't delete sibling fixtures (72e4b5578)
❤️ Contributors
- Daniel Roe (@danielroe)
- Florian Heuberger (@Flo0806)
- Matej Černý (@cernymatej)
- bdbch (@bdbch)
- Elecmonkey (@elecmonkey)
- Ryota Watanabe (@wattanx)
- kealan (@KealanAU)
- Julien Huang (@huang-julien)
- Luke Nelson (@luc122c)
- Harlan Wilton (@harlan-zw)
- Mateleo (@Mateleo)
- lutejka (@lutejka)
- Darlan José Batista do Prado (@DarlanPrado)
- Max (@onmax)
- Sushant (@sushantguri)
- raminjafary (@raminjafary)