⚠️ This is a security release. We recommend upgrading as soon as possible with
npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
🩹 Fixes
- nuxt: Clear hide/reset timeouts in set() (#35534)
- nuxt: Preserve trailing slash in NuxtLink href when unset (#35501)
- vite: Resolve SSR inlined CSS module class name mismatch (#35610)
- nuxt: Sync layout meta during middleware on SSR (#35633)
- nuxt: Update client URL to match SSR on fatal middleware error (#35637)
- nuxt: Watch external component directories in development (#35652)
- nuxt: Don't cross-pollute useAsyncData cache on reactive key change (#35656)
- nuxt: Return global route for
useRoutein detached effect scope (#35659) - nuxt: Ignore custom
nameorpathwhen reusing an existing page in ()