SCA: security update for @nuxt/devtools (GHSA-rcvg-rgf7-pppv)

high Tenable Cloud Security Plugin ID 418675

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js.
Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to
path traversal. Combined with a lack of Origin checks on the WebSocket handler, an attacker is able to
interact with a locally running devtools instance and exfiltrate data abusing this vulnerability. In
certain configurations an attacker could leak the devtools authentication token and then abuse other RPC
functions to achieve RCE. The `getTextAssetContent` function does not check for path traversals, this
could allow an attacker to read arbitrary files over the RPC WebSocket. The WebSocket server does not
check the origin of the request leading to cross-site-websocket-hijacking. This may be intentional to
allow certain configurations to work correctly. Nuxt Devtools authentication tokens are placed within the
home directory of the current user. The malicious webpage can connect to the Devtools WebSocket, perform a
directory traversal brute force to find the authentication token, then use the *authenticated*
`writeStaticAssets` function to create a new Component, Nitro Handler or `app.vue` file which will run
automatically as the file is changed. This vulnerability has been addressed in release version 1.3.9. All
users are advised to upgrade. There are no known workarounds for this vulnerability. (CVE-2024-23657)

See Also

https://github.com/advisories/GHSA-rcvg-rgf7-pppv

Plugin Details

Severity: High

ID: 418675

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-23657

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.7

Threat Score: 6.8

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/5/2024

Vulnerability Publication Date: 8/5/2024

Reference Information

CVE: CVE-2024-23657