nuxt / nuxt/devtools

v1: auth-page innerHTML XSS (CVE-2025-52662) — fix 7cadbbe9 only on main

Open
#988 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
3.3k
Forks
214
Avg merge
13h 22m
Merged PRs (30d)
18

Description

Hi — flagging a likely missing backport on the v1 branch.

CVE-2025-52662 was fixed by 7cadbbe9 on the default branch ("using textContent instead of innerHTML for auth page"). The patch swaps an innerHTML write to textContent inside packages/devtools/src/runtime/auth/index.html, eliminating a DOM-XSS sink fed by the Bearer query parameter.

A few facts that suggest the fix did not reach v1:

  • compare v1...7cadbbe9ahead_by=125, behind_by=0 (i.e. v1 strictly lacks the fix path)
  • packages/devtools/src/runtime/auth/index.html exists on v1 and still contains innerHTML-based assignment (the pre-patch shape)
  • No prior issue/PR references CVE-2025-52662 in this repo
  • Last commit on v1 is 2025-01-02, so the branch is not totally inactive

If v1 is still considered a maintained line for users on the older Nuxt-DevTools major, a one-commit cherry-pick of 7cadbbe9 onto v1 would close the gap. The patch is a single small file edit and should not collide with anything else.

Happy to open the cherry-pick PR if it would help. If v1 is end-of-life and users should upgrade, that's also a clear answer — please close in that case so I don't re-surface it.

Thanks for maintaining devtools!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

First inspect packages/devtools/src/runtime/auth/index.html on v1 and compare it with commit 7cadbbe9 to confirm the vulnerable assignment and the intended backport. Check whether v1 is still maintained; if so, apply the single-commit change and verify that the auth page no longer writes the Bearer query parameter through innerHTML.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
authentication, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.