CVE-2025-24361: Opening a malicious website while running a Nuxt dev server could allow read-only access to code
(updated )
Source code may be stolen during dev when using webpack / rspack builder and you open a malicious web site.
References
Detect and mitigate CVE-2025-24361 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →