You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
That CORS handler sets Access-Control-Allow-Origin: *.
Important
If on an affected version, it may be possible to opt-out of the default Nuxt CORS handler by configuring vite.server.cors.
PoC
Start a dev server in any nuxt project using Vite by nuxt dev.
Send a fetch request to http://localhost:3000/_nuxt/app.vue (fetch('http://localhost:3000/_nuxt/app.vue')) from a different origin page.
Impact
Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites
Additional Information
/__nuxt_vite_node__/manifest / /__nuxt_vite_node__/module also seems to have Access-Control-Allow-Origin: *, so it maybe also possible to exploit that handler.
Although I didn't find a valid module id.
Note that this handler is probably also vulnerable to DNS rebinding attacks as I didn't find any host header checks.
Summary
Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings.
Details
While Vite patched the default CORS settings to fix GHSA-vg6x-rcgg-rjx6, nuxt uses its own CORS handler by default (#23995).
nuxt/packages/vite/src/client.ts
Lines 257 to 263 in 7d345c7
That CORS handler sets
Access-Control-Allow-Origin: *
.Important
If on an affected version, it may be possible to opt-out of the default Nuxt CORS handler by configuring
vite.server.cors
.PoC
nuxt dev
.http://localhost:3000/_nuxt/app.vue
(fetch('http://localhost:3000/_nuxt/app.vue')
) from a different origin page.Impact
Users with the default server.cors option using Vite builder may get the source code stolen by malicious websites
Additional Information
/__nuxt_vite_node__/manifest
//__nuxt_vite_node__/module
also seems to haveAccess-Control-Allow-Origin: *
, so it maybe also possible to exploit that handler.nuxt/packages/vite/src/vite-node.ts
Line 39 in 7d345c7
Although I didn't find a valid module id.
Note that this handler is probably also vulnerable to DNS rebinding attacks as I didn't find any host header checks.