MEDIUM6.9
GHSA-xmq3-q5pm-rp26
Nuxt DevTools vulnerable to cross-site scripting (XSS)
Quick fix
GHSA-xmq3-q5pm-rp26 — @nuxt/devtools: upgrade to the fixed version with the command below.
npm install @nuxt/devtools@2.6.4Details
A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.
Are you affected?
Enter the version of the package you're using.