⚠️ This is a security release. We recommend upgrading as soon as possible with
npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the cache, swr or isr route rules, purge any CDN or edge cache after upgrading; a leaked _payload.json may already be cached upstream.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
🔥 Performance
- nitro: Replace island teleports in a single html pass (#35515)
- nuxt: Add
vue.optionsApiand disable it for v5+ (#35791) - nuxt: Without pages, skip client plugins that require routing (#35794)
- nuxt: Skip payload revival plugin when
ssr: false(#35782)