⚠️ This is a security release. We recommend upgrading as soon as possible with
npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the cache, swr or isr route rules, purge any CDN or edge cache after upgrading; a leaked _payload.json may already be cached upstream.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
🔥 Performance
- nitro: Replace island teleports in a single html pass (#35515)
- nuxt: Add
vue.optionsApiand disable it for v5+ (#35791) - nuxt: Without pages, skip client plugins that require routing (#35794)
- nuxt: Skip payload revival plugin when
ssr: false(#35782)
🩹 Fixes
- nitro: Read rspack dev output fs lazily for server entry (#35740)
- rspack,webpack: Resolve loaders and runtime deps from nuxt dirs (#35568)
- nuxt: Return global route for
useRoutein detached effect scope (#35659) - nuxt: Ignore custom
nameorpathwhen reusing an existing page inpages:extend(#35661) - nuxt: Render client components in nested server components (#35669)
- nuxt: Preserve explicit
useFetchmethod inference (#35671) - nuxt: Revalidate cached route payloads instead of using
force-cache(#35672) - nuxt: Correct default export detection in plugin metadata (#35676)
- nuxt: Clear hide/reset timeouts in set() (#35534)
- kit,nuxt,rspack,schema,webpack: Add
.mtsfile extension in resolver (#33845) - nuxt: Preserve trailing slash in NuxtLink href when unset (#35501)
- nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#35656)
- nuxt: Filter plugin dependencies by build target (#35682)
- nuxt: Reload real page module on HMR of JSX render-function pages (#35678)
- nuxt: Resolve
@unhead/vue/*from nuxt's dependency tree (#35690) - kit: Surface module load errors instead of masking as missing (#35497)
- nuxt: Type auto-imported
$fetchwith nitro's$Fetch(#35704) - nuxt: Don't reference app config sources in shared and node tsconfigs (#35673)
- vite: Resolve SSR inlined CSS module class name mismatch (#35610)
- nuxt: Generate layout types even when pages module is disabled (#35717)
- nitro: Skip resource hints for stylesheets already rendered as blocking links (#35691)
- kit: Dedupe layers that are both auto-scanned and explicitly extended (#35712)
- nuxt: Don't apply scroll behaviour after a subsequent nav (#35719)
- vite: Ensure server sourcemap-preserver plugin actually runs (#35680)
- vite: Preserve css suffix when extracting ssr inline styles (#35714)
- nuxt: Watch external component directories in development (#35652)
- nuxt: Don't exclude client entry module from style extraction (#35720)
- nuxt: Amend cleanup command in NUXT_B7014 error message (#35735)
- nuxt: Only pull in
vue-routerwhen there are island pages (#35739) - vite: Suppress external warnings for internal vite-node paths (#35744)
- nuxt: Use scope-aware oxc parser for auto-imports (#35743)
- nuxt: Sync layout meta during middleware on SSR (#35633)
- nitro: Add alias for
h3that pins it to the version nuxt depends on (#35774) - nuxt: Preserve query params in cached payload extraction (#35696)
- nuxt: Mirror runtime route tree in generated typed-router types (#35788)
- nuxt: Warn when an imports preset
fromcannot be resolved (#35799) - kit: Avoid mutating layer configs when resolving options (#35729)
- nuxt: Convert inline route rules exactly or drop with a warning (#35455)
- nitro,nuxt,vite: Dedupe and normalise global css links in dev (#35834)
- vite: Register template HMR plugin on dev servers (929c6c138)
- nuxt: Remove dev error overlay when error is cleared (#35821)
- rspack,webpack: Resolve bundled postcss defaults from builder (#35823)
- schema: Normalise slashes in
app.buildAssetsDir(#35833) - nitro: Bound island props and v-for to prevent unauthenticated DoS (4e35ae9ba)
- nitro: Confine runtime payload cache to prerendering (ac9b41a36)
- nuxt: Case-fold route rule keys to match folded lookups (ad624a75a)
- nitro: Require loopback peer for chrome devtools workspace endpoint (0769c4f9b)
- nuxt: Reject reserved
templateisland prop under runtime compiler (ee6c84633) - nuxt: Reject top-level
asprop for islands (581651ff3)
💅 Refactors
- nuxt: Use tick based debounce for asyncData executes (#34151)
- kit,nuxt: Replace
semverwithverkit(#35713) - rspack,webpack: Use DI model to split builders (#35751)
📖 Documentation
- Add dev container setup guide (#35665)
- Fix dev container setup guide (#35666)
- Add explanation of 200.html and 404.html SPA fallbacks (#34483)
- Expand payload extraction documentation (#35648)
- Clarify NuxtLink componentName is the internal (devtools) name (#35658)
- Add example for components dir pattern option (#35663)
- Require a single root element (#35677)
- Add reason for why you should never import Vue app code in nitro code (#34481)
- Document disabling code-splitting with
codeSplitting: false(#35683) - Document nuxt-client caveat for non-SFC components (#35654)
- Clarify favicon does not use cdnURL by default (#35681)
- Standardize section order and headings across docs (#35685)
- Clarify
onPrehydrateexample comment (#35684) - Add useId as a known limitation of nuxt island (#35693)
- Recommend status over pending in data fetching (#35694)
- Fill gaps in API minimalVersion badges after #34485 (#35708, #34485)
- Explain dynamic asset paths (#35695)
- Document
runtimeConfigenv var casting edge cases (#35709) - Clarify module dependency resolution (#35718)
- Add more writing guidelines (#35662)
- Add note with alternatives to using remote layers (#35721)
- Use
nuxtrather thannuxi(8891e179c) - Document relative baseURL workarounds (#34004)
- Warn about
runtimeCompilersecurity best practices (449b63ab1) - Warn about validating server component props (2c981cb07)
📦 Build
- nitro: Re-export type from augments to preserve module (dac937675)
- nuxt: Remove
.tsfile extension fromruntime/imports (#35689) - ui-templates: Commit generated ui template files (#35770)
🏡 Chore
- Add extension 🤦 (d595fb3d4)
- Move to pnpm catalogs (#35748)
- Update knip config, resolve issues, and run in ci (#35742)
- Ignore
@nuxt/telemetryin knip (9824d4f10) - ui-templates: Pass config file path to unocss (34e7a810d)
- Allow regenerating lockfile in release script (c31389df3)
- nuxt: Bump
@nuxt/devtoolsto v3.3.1 (#35815) - Ensure types are setup before unit tests (784d8f700)
- Simplify knip configuration (#35827)
✅ Tests
- Reproduce duplicate CSS in shared chunks (#35649)
- Prepare fixtures automatically before fixture and e2e runs (e8b3e6411)
- Improve and refactor basic fixture (#35687)
- Slim down client-only, chunk-error and axis-independent suites (#35706)
- Do not run type checking when benchmarking nuxt build (6355f3bc9)
- kit: Scope loadNuxt temp dir so it doesn't delete sibling fixtures (37301dd51)
- Guard against transient undefined
_routein gotoPath (ca92d082b) - Retry fixture prepare on transient ENOTEMPTY (3a6b59f96)
- Raise route-HMR polling timeout to reduce e2e flakiness (01dc27b7e)
- Update bundle size snapshot (30d24817c)
🤖 CI
- Rebalance shards and drop non-vite windows fixtures (#35700)
- Warm windows dependency cache on main (#35730)
- Run knip in default and production modes (#35745)
- Run knip on pull requests (d620aa972)
- Prepare tests (c7bf7f738)
- Also prepare tests in
knipjob (58f68bd64) - Check internal docs links on pull requests and all links weekly (#35767)
❤️ Contributors
- Daniel Roe (@danielroe)
- Lars Kappert (@webpro)
- Matej Černý (@cernymatej)
- Anthony Fu (@antfu)
- Harlan Wilton (@harlan-zw)
- Florian Heuberger (@Flo0806)
- Anoesj Sadraee (@Anoesj)
- Ryota Watanabe (@wattanx)
- Alexander Lichter (@TheAlexLichter)
- Nestor Vera (@hacknug)
- Mateleo (@Mateleo)
- Kevin Deng (@sxzz)
- Robin (@OrbisK)
- Bochkarev Ivan (@Ibochkarev)
- Quentin Macq (@quentinmcq)
- Julien Huang (@huang-julien)
- Max (@onmax)
- Luke Nelson (@luc122c)
- Darlan José Batista do Prado (@DarlanPrado)
- kealan (@KealanAU)
- Sushant (@sushantguri)
- raminjafary (@raminjafary)
- Aubakirov Asker (@Askerka00)
- lutejka (@lutejka)
- Amulet Iris (@KazariAI)
- bdbch (@bdbch)
- Elecmonkey (@elecmonkey)