<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:12:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329251</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329251</link>
      <description>EUVD-2026-329251</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329251</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56301</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56301</link>
      <description>&lt;p&gt;Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and connect. Unprivileged co-resident users can exploit the unprotected module request handler to read arbitrary files such as .env and SSH keys through the SSR plugin pipeline. Production builds are unaffected, as the IPC server runs only in development.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and connect. Unprivileged co-resident users can exploit the unprotected module request handler to read arbitrary files such as .env and SSH keys through the SSR plugin pipeline. Production builds are unaffected, as the IPC server runs only in development.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56301</guid>
    </item>
    <item>
      <title>GHSA-534h-c3cw-v3h9 — Nuxt dev server vite-node IPC socket is world-connectable on Linux</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-534h-c3cw-v3h9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When running `nuxt dev` on Linux (Node.js 20+, outside Docker / StackBlitz), Nuxt&amp;#39;s internal vite-node IPC server binds to a Linux abstract-namespace Unix socket (`\0nuxt-vite-node-&amp;lt;pid&amp;gt;-&amp;lt;ts&amp;gt;.sock`). Abstract sockets have no filesystem inode and therefore no permission bits: any local UID on the host that can read `/proc/net/unix` can enumerate the socket and connect to it.&lt;/p&gt;
&lt;p&gt;The IPC server does not perform any peer-credential or shared-secret check before dispatching requests. The `module` request type passes its `moduleId` field straight into Vite&amp;#39;s SSR `fetchModule()`, which is not gated by Vite&amp;#39;s HTTP-layer `server.fs.allow` deny-list. A co-resident unprivileged local user can therefore request paths like `/home/&amp;lt;dev&amp;gt;/project/.env?raw` or `~/.ssh/id_rsa?raw` and read the developer&amp;#39;s secrets through the dev server&amp;#39;s SSR plugin pipeline. The `resolve` request type additionally enables filesystem probing.&lt;/p&gt;
&lt;p&gt;This affects developers running `nuxt dev` on shared multi-tenant Linux hosts (lab machines, shared bastions, CI runners shared between jobs without per-job container isolation). It does not affect:&lt;/p&gt;
&lt;p&gt;- Production builds (`nuxt build` / `nuxt start`). The IPC server only runs in development.
- macOS or Windows developers.
- Docker / StackBlitz environments, which already fall back to a filesystem socket.
- Single-user laptops or per-job containerised CI.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in `nuxt@4.4.7` (commit [`1f9f4767`](https://github.com/nuxt/nuxt/commit/1f9f4767a8725104…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When running `nuxt dev` on Linux (Node.js 20+, outside Docker / StackBlitz), Nuxt&amp;#39;s internal vite-node IPC server binds to a Linux abstract-namespace Unix socket (`\0nuxt-vite-node-&amp;lt;pid&amp;gt;-&amp;lt;ts&amp;gt;.sock`). Abstract sockets have no filesystem inode and therefore no permission bits: any local UID on the host that can read `/proc/net/unix` can enumerate the socket and connect to it.&lt;/p&gt;
&lt;p&gt;The IPC server does not perform any peer-credential or shared-secret check before dispatching requests. The `module` request type passes its `moduleId` field straight into Vite&amp;#39;s SSR `fetchModule()`, which is not gated by Vite&amp;#39;s HTTP-layer `server.fs.allow` deny-list. A co-resident unprivileged local user can therefore request paths like `/home/&amp;lt;dev&amp;gt;/project/.env?raw` or `~/.ssh/id_rsa?raw` and read the developer&amp;#39;s secrets through the dev server&amp;#39;s SSR plugin pipeline. The `resolve` request type additionally enables filesystem probing.&lt;/p&gt;
&lt;p&gt;This affects developers running `nuxt dev` on shared multi-tenant Linux hosts (lab machines, shared bastions, CI runners shared between jobs without per-job container isolation). It does not affect:&lt;/p&gt;
&lt;p&gt;- Production builds (`nuxt build` / `nuxt start`). The IPC server only runs in development.
- macOS or Windows developers.
- Docker / StackBlitz environments, which already fall back to a filesystem socket.
- Single-user laptops or per-job containerised CI.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in `nuxt@4.4.7` (commit [`1f9f4767`](https://github.com/nuxt/nuxt/commit/1f9f4767a8725104…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-534h-c3cw-v3h9</guid>
    </item>
  </channel>
</rss>
