yarn nuxt 3.21.10

5 hours ago

⚠️ This is a security release. We recommend upgrading as soon as possible with npx nuxt upgrade --dedupe.

It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.

If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.

Full details: Nuxt Security Patch Releases and GitHub Security Advisories.

👉 Changelog

compare changes

🩹 Fixes

  • nuxt: Clear hide/reset timeouts in set() (#35534)
  • nuxt: Preserve trailing slash in NuxtLink href when unset (#35501)
  • vite: Resolve SSR inlined CSS module class name mismatch (#35610)
  • nuxt: Sync layout meta during middleware on SSR (#35633)
  • nuxt: Update client URL to match SSR on fatal middleware error (#35637)
  • nuxt: Watch external component directories in development (#35652)
  • nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#35656)
  • nuxt: Return global route for useRoute in detached effect scope (#35659)
  • nuxt: Ignore custom name or path when reusing an existing page in pages:extend (#35661)
  • nuxt: Preserve explicit useFetch method inference (#35671)
  • nuxt: Correct default export detection in plugin metadata (#35676)
  • nuxt: Reload real page module on HMR of JSX render-function pages (#35678)
  • vite: Ensure server sourcemap-preserver plugin actually runs (#35680)
  • nuxt: Resolve @unhead/vue/* from nuxt's dependency tree (#35690)
  • nuxt: Don't apply scroll behaviour after a subsequent nav (#35719)
  • vite: Preserve css suffix when extracting ssr inline styles (#35714)
  • nuxt: Don't exclude client entry module from style extraction (#35720)
  • kit: Avoid mutating layer configs when resolving options (#35729)
  • nuxt: Generate layout types even when pages module is disabled (#35717)
  • nitro: Skip resource hints for stylesheets already rendered as blocking links (#35691)
  • nuxt: Revalidate cached route payloads instead of using force-cache (#35672)
  • nuxt: Preserve query params in cached payload extraction (#35696)
  • rspack,webpack: Resolve loaders and runtime deps from nuxt dirs (#35568)
  • nuxt: Render client components in nested server components (#35669)
  • nuxt: Remove dev error overlay when error is cleared (#35821)
  • rspack,webpack: Resolve bundled postcss defaults from builder (#35823)
  • schema: Normalise slashes in app.buildAssetsDir (#35833)
  • nuxt: Case-fold route rule keys to match folded lookups (619963309)
  • nitro: Require loopback peer for chrome devtools workspace endpoint (00f71bb65)
  • nitro: Bound island props and v-for to prevent unauthenticated DoS (668cdfdfd)
  • nuxt: Reject reserved template island prop under runtime compiler (5b60017f7)
  • nuxt: Reject top-level as prop for islands (00a2b0494)

📖 Documentation

  • Document relative baseURL workarounds (#34004)
  • Warn about runtimeCompiler security best practices (b76c1a8bd)
  • Warn about validating server component props (f6d72628d)

✅ Tests

  • Guard against transient undefined _route in gotoPath (5391e7e6a)
  • Raise route-HMR polling timeout to reduce e2e flakiness (cbc757c63)
  • kit: Scope loadNuxt temp dir so it doesn't delete sibling fixtures (72e4b5578)

❤️ Contributors

Don't miss a new nuxt release

NewReleases is sending notifications on new releases.