CVE-2025-24360
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 25, 2025
CWE ID 200
Summary
CVE-2025-24360 is a vulnerability affecting Nuxt, an open-source web development framework for Vue.js. Prior to version 3.15.3, Nuxt's default CORS settings allowed any websites to send requests to the development server and read the response. This issue posed a risk for users building their websites using Vite builder, as malicious sites could potentially steal sensitive source code. The vulnerability, which began in Nuxt version 3.8.1, has now been addressed with the release of version 3.15.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.