Medium severity6.9NVD Advisory· Published Nov 7, 2025· Updated Jun 17, 2026
CVE-2025-52662
CVE-2025-52662
Description
A vulnerability in Nuxt DevTools has been fixed in version 2.6.4*. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.
More details: https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@nuxt/devtoolsnpm | < 2.6.4 | 2.6.4 |
Affected products
3- Range: 2.6.3
Patches
Vulnerability mechanics
References
5- github.com/nuxt/devtools/commit/7cadbbe9nvdPatchWEB
- vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtoolsnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xmq3-q5pm-rp26ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-52662ghsaADVISORY
- github.com/nuxt/devtools/releases/tag/v2.6.4ghsaWEB
News mentions
0No linked articles in our index yet.