
Oops! I gave Nuxt permissions to delete files
Program With Erik
⚠️ This is a security release. We recommend upgrading as soon as possible with
npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/[email protected], which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
useRoute in detached effect scope (#35659)name or path when reusing an existing page in pages:extend (#35661)useFetch method inference (#35671)@unhead/vue/* from nuxt's dependency tree (#35690)force-cache (#35672)app.buildAssetsDir (#35833)template island prop under runtime compiler (5b60017f7)as prop for islands (00a2b0494)runtimeCompiler security best practices (b76c1a8bd)_route in gotoPath (5391e7e6a)