npm nuxt 4.5.1

latest release: 3.21.10
6 hours ago

⚠️ This is a security release. We recommend upgrading as soon as possible with npx nuxt upgrade --dedupe.

It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.

If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.

If you use the cache, swr or isr route rules, purge any CDN or edge cache after upgrading; a leaked _payload.json may already be cached upstream.

Full details: Nuxt Security Patch Releases and GitHub Security Advisories.

👉 Changelog

compare changes

🔥 Performance

  • nitro: Replace island teleports in a single html pass (#35515)
  • nuxt: Add vue.optionsApi and disable it for v5+ (#35791)
  • nuxt: Without pages, skip client plugins that require routing (#35794)
  • nuxt: Skip payload revival plugin when ssr: false (#35782)

🩹 Fixes

  • nitro: Read rspack dev output fs lazily for server entry (#35740)
  • rspack,webpack: Resolve loaders and runtime deps from nuxt dirs (#35568)
  • nuxt: Return global route for useRoute in detached effect scope (#35659)
  • nuxt: Ignore custom name or path when reusing an existing page in pages:extend (#35661)
  • nuxt: Render client components in nested server components (#35669)
  • nuxt: Preserve explicit useFetch method inference (#35671)
  • nuxt: Revalidate cached route payloads instead of using force-cache (#35672)
  • nuxt: Correct default export detection in plugin metadata (#35676)
  • nuxt: Clear hide/reset timeouts in set() (#35534)
  • kit,nuxt,rspack,schema,webpack: Add .mts file extension in resolver (#33845)
  • nuxt: Preserve trailing slash in NuxtLink href when unset (#35501)
  • nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#35656)
  • nuxt: Filter plugin dependencies by build target (#35682)
  • nuxt: Reload real page module on HMR of JSX render-function pages (#35678)
  • nuxt: Resolve @unhead/vue/* from nuxt's dependency tree (#35690)
  • kit: Surface module load errors instead of masking as missing (#35497)
  • nuxt: Type auto-imported $fetch with nitro's $Fetch (#35704)
  • nuxt: Don't reference app config sources in shared and node tsconfigs (#35673)
  • vite: Resolve SSR inlined CSS module class name mismatch (#35610)
  • nuxt: Generate layout types even when pages module is disabled (#35717)
  • nitro: Skip resource hints for stylesheets already rendered as blocking links (#35691)
  • kit: Dedupe layers that are both auto-scanned and explicitly extended (#35712)
  • nuxt: Don't apply scroll behaviour after a subsequent nav (#35719)
  • vite: Ensure server sourcemap-preserver plugin actually runs (#35680)
  • vite: Preserve css suffix when extracting ssr inline styles (#35714)
  • nuxt: Watch external component directories in development (#35652)
  • nuxt: Don't exclude client entry module from style extraction (#35720)
  • nuxt: Amend cleanup command in NUXT_B7014 error message (#35735)
  • nuxt: Only pull in vue-router when there are island pages (#35739)
  • vite: Suppress external warnings for internal vite-node paths (#35744)
  • nuxt: Use scope-aware oxc parser for auto-imports (#35743)
  • nuxt: Sync layout meta during middleware on SSR (#35633)
  • nitro: Add alias for h3 that pins it to the version nuxt depends on (#35774)
  • nuxt: Preserve query params in cached payload extraction (#35696)
  • nuxt: Mirror runtime route tree in generated typed-router types (#35788)
  • nuxt: Warn when an imports preset from cannot be resolved (#35799)
  • kit: Avoid mutating layer configs when resolving options (#35729)
  • nuxt: Convert inline route rules exactly or drop with a warning (#35455)
  • nitro,nuxt,vite: Dedupe and normalise global css links in dev (#35834)
  • vite: Register template HMR plugin on dev servers (929c6c138)
  • nuxt: Remove dev error overlay when error is cleared (#35821)
  • rspack,webpack: Resolve bundled postcss defaults from builder (#35823)
  • schema: Normalise slashes in app.buildAssetsDir (#35833)
  • nitro: Bound island props and v-for to prevent unauthenticated DoS (4e35ae9ba)
  • nitro: Confine runtime payload cache to prerendering (ac9b41a36)
  • nuxt: Case-fold route rule keys to match folded lookups (ad624a75a)
  • nitro: Require loopback peer for chrome devtools workspace endpoint (0769c4f9b)
  • nuxt: Reject reserved template island prop under runtime compiler (ee6c84633)
  • nuxt: Reject top-level as prop for islands (581651ff3)

💅 Refactors

  • nuxt: Use tick based debounce for asyncData executes (#34151)
  • kit,nuxt: Replace semver with verkit (#35713)
  • rspack,webpack: Use DI model to split builders (#35751)

📖 Documentation

  • Add dev container setup guide (#35665)
  • Fix dev container setup guide (#35666)
  • Add explanation of 200.html and 404.html SPA fallbacks (#34483)
  • Expand payload extraction documentation (#35648)
  • Clarify NuxtLink componentName is the internal (devtools) name (#35658)
  • Add example for components dir pattern option (#35663)
  • Require a single root element (#35677)
  • Add reason for why you should never import Vue app code in nitro code (#34481)
  • Document disabling code-splitting with codeSplitting: false (#35683)
  • Document nuxt-client caveat for non-SFC components (#35654)
  • Clarify favicon does not use cdnURL by default (#35681)
  • Standardize section order and headings across docs (#35685)
  • Clarify onPrehydrate example comment (#35684)
  • Add useId as a known limitation of nuxt island (#35693)
  • Recommend status over pending in data fetching (#35694)
  • Fill gaps in API minimalVersion badges after #34485 (#35708, #34485)
  • Explain dynamic asset paths (#35695)
  • Document runtimeConfig env var casting edge cases (#35709)
  • Clarify module dependency resolution (#35718)
  • Add more writing guidelines (#35662)
  • Add note with alternatives to using remote layers (#35721)
  • Use nuxt rather than nuxi (8891e179c)
  • Document relative baseURL workarounds (#34004)
  • Warn about runtimeCompiler security best practices (449b63ab1)
  • Warn about validating server component props (2c981cb07)

📦 Build

  • nitro: Re-export type from augments to preserve module (dac937675)
  • nuxt: Remove .ts file extension from runtime/ imports (#35689)
  • ui-templates: Commit generated ui template files (#35770)

🏡 Chore

  • Add extension 🤦 (d595fb3d4)
  • Move to pnpm catalogs (#35748)
  • Update knip config, resolve issues, and run in ci (#35742)
  • Ignore @nuxt/telemetry in knip (9824d4f10)
  • ui-templates: Pass config file path to unocss (34e7a810d)
  • Allow regenerating lockfile in release script (c31389df3)
  • nuxt: Bump @nuxt/devtools to v3.3.1 (#35815)
  • Ensure types are setup before unit tests (784d8f700)
  • Simplify knip configuration (#35827)

✅ Tests

  • Reproduce duplicate CSS in shared chunks (#35649)
  • Prepare fixtures automatically before fixture and e2e runs (e8b3e6411)
  • Improve and refactor basic fixture (#35687)
  • Slim down client-only, chunk-error and axis-independent suites (#35706)
  • Do not run type checking when benchmarking nuxt build (6355f3bc9)
  • kit: Scope loadNuxt temp dir so it doesn't delete sibling fixtures (37301dd51)
  • Guard against transient undefined _route in gotoPath (ca92d082b)
  • Retry fixture prepare on transient ENOTEMPTY (3a6b59f96)
  • Raise route-HMR polling timeout to reduce e2e flakiness (01dc27b7e)
  • Update bundle size snapshot (30d24817c)

🤖 CI

  • Rebalance shards and drop non-vite windows fixtures (#35700)
  • Warm windows dependency cache on main (#35730)
  • Run knip in default and production modes (#35745)
  • Run knip on pull requests (d620aa972)
  • Prepare tests (c7bf7f738)
  • Also prepare tests in knip job (58f68bd64)
  • Check internal docs links on pull requests and all links weekly (#35767)

❤️ Contributors

Don't miss a new nuxt release

NewReleases is sending notifications on new releases.