⚠️This is a security release. We recommend upgrading as soon as possible with npx nuxt upgrade --dedupe.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in @nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the cache, swr or isr route rules, purge any CDN or edge cache after upgrading; a leaked _payload.json may already be cached upstream.
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [nuxt](https://nuxt.com) ([source](https://github.com/nuxt/nuxt/tree/HEAD/packages/nuxt)) | [`4.5.0` → `4.5.1`](https://renovatebot.com/diffs/npm/nuxt/4.5.0/4.5.1) |  |  |
---
### Release Notes
<details>
<summary>nuxt/nuxt (nuxt)</summary>
### [`v4.5.1`](https://github.com/nuxt/nuxt/releases/tag/v4.5.1)
[Compare Source](https://github.com/nuxt/nuxt/compare/v4.5.0...v4.5.1)
> ⚠️ **This is a security release.** We recommend upgrading as soon as possible with `npx nuxt upgrade --dedupe`.
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in `@nuxt/devtools@3.3.1`, which fixes a separate critical development-only RCE.
If you already upgraded for the earlier route rule advisory ([CVE-2026-53721](https://github.com/nuxt/nuxt/security/advisories/GHSA-mm7m-92g8-7m47)), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the `cache`, `swr` or `isr` route rules, purge any CDN or edge cache after upgrading; a leaked `_payload.json` may already be cached upstream.
Full details: [Nuxt Security Patch Releases](https://nuxt.com/blog/v4-5-security) and [GitHub Security Advisories](https://github.com/nuxt/nuxt/security/advisories).
#### 👉 Changelog
[compare changes](https://github.com/nuxt/nuxt/compare/v4.5.0...v4.5.1)
##### 🔥 Performance
- **nitro:** Replace island teleports in a single html pass ([#​35515](https://github.com/nuxt/nuxt/pull/35515))
- **nuxt:** Add `vue.optionsApi` and disable it for v5+ ([#​35791](https://github.com/nuxt/nuxt/pull/35791))
- **nuxt:** Without pages, skip client plugins that require routing ([#​35794](https://github.com/nuxt/nuxt/pull/35794))
- **nuxt:** Skip payload revival plugin when `ssr: false` ([#​35782](https://github.com/nuxt/nuxt/pull/35782))
##### 🩹 Fixes
- **nitro:** Read rspack dev output fs lazily for server entry ([#​35740](https://github.com/nuxt/nuxt/pull/35740))
- **rspack,webpack:** Resolve loaders and runtime deps from nuxt dirs ([#​35568](https://github.com/nuxt/nuxt/pull/35568))
- **nuxt:** Return global route for `useRoute` in detached effect scope ([#​35659](https://github.com/nuxt/nuxt/pull/35659))
- **nuxt:** Ignore custom `name` or `path` when reusing an existing page in `pages:extend` ([#​35661](https://github.com/nuxt/nuxt/pull/35661))
- **nuxt:** Render client components in nested server components ([#​35669](https://github.com/nuxt/nuxt/pull/35669))
- **nuxt:** Preserve explicit `useFetch` method inference ([#​35671](https://github.com/nuxt/nuxt/pull/35671))
- **nuxt:** Revalidate cached route payloads instead of using `force-cache` ([#​35672](https://github.com/nuxt/nuxt/pull/35672))
- **nuxt:** Correct default export detection in plugin metadata ([#​35676](https://github.com/nuxt/nuxt/pull/35676))
- **nuxt:** Clear hide/reset timeouts in set() ([#​35534](https://github.com/nuxt/nuxt/pull/35534))
- **kit,nuxt,rspack,schema,webpack:** Add `.mts` file extension in resolver ([#​33845](https://github.com/nuxt/nuxt/pull/33845))
- **nuxt:** Preserve trailing slash in NuxtLink href when unset ([#​35501](https://github.com/nuxt/nuxt/pull/35501))
- **nuxt:** Don't cross-pollute useAsyncData cache on reactive key change ([#​35656](https://github.com/nuxt/nuxt/pull/35656))
- **nuxt:** Filter plugin dependencies by build target ([#​35682](https://github.com/nuxt/nuxt/pull/35682))
- **nuxt:** Reload real page module on HMR of JSX render-function pages ([#​35678](https://github.com/nuxt/nuxt/pull/35678))
- **nuxt:** Resolve `@unhead/vue/*` from nuxt's dependency tree ([#​35690](https://github.com/nuxt/nuxt/pull/35690))
- **kit:** Surface module load errors instead of masking as missing ([#​35497](https://github.com/nuxt/nuxt/pull/35497))
- **nuxt:** Type auto-imported `$fetch` with nitro's `$Fetch` ([#​35704](https://github.com/nuxt/nuxt/pull/35704))
- **nuxt:** Don't reference app config sources in shared and node tsconfigs ([#​35673](https://github.com/nuxt/nuxt/pull/35673))
- **vite:** Resolve SSR inlined CSS module class name mismatch ([#​35610](https://github.com/nuxt/nuxt/pull/35610))
- **nuxt:** Generate layout types even when pages module is disabled ([#​35717](https://github.com/nuxt/nuxt/pull/35717))
- **nitro:** Skip resource hints for stylesheets already rendered as blocking links ([#​35691](https://github.com/nuxt/nuxt/pull/35691))
- **kit:** Dedupe layers that are both auto-scanned and explicitly extended ([#​35712](https://github.com/nuxt/nuxt/pull/35712))
- **nuxt:** Don't apply scroll behaviour after a subsequent nav ([#​35719](https://github.com/nuxt/nuxt/pull/35719))
- **vite:** Ensure server sourcemap-preserver plugin actually runs ([#​35680](https://github.com/nuxt/nuxt/pull/35680))
- **vite:** Preserve css suffix when extracting ssr inline styles ([#​35714](https://github.com/nuxt/nuxt/pull/35714))
- **nuxt:** Watch external component directories in development ([#​35652](https://github.com/nuxt/nuxt/pull/35652))
- **nuxt:** Don't exclude client entry module from style extraction ([#​35720](https://github.com/nuxt/nuxt/pull/35720))
- **nuxt:** Amend cleanup command in NUXT\_B7014 error message ([#​35735](https://github.com/nuxt/nuxt/pull/35735))
- **nuxt:** Only pull in `vue-router` when there are island pages ([#​35739](https://github.com/nuxt/nuxt/pull/35739))
- **vite:** Suppress external warnings for internal vite-node paths ([#​35744](https://github.com/nuxt/nuxt/pull/35744))
- **nuxt:** Use scope-aware oxc parser for auto-imports ([#​35743](https://github.com/nuxt/nuxt/pull/35743))
- **nuxt:** Sync layout meta during middleware on SSR ([#​35633](https://github.com/nuxt/nuxt/pull/35633))
- **nitro:** Add alias for `h3` that pins it to the version nuxt depends on ([#​35774](https://github.com/nuxt/nuxt/pull/35774))
- **nuxt:** Preserve query params in cached payload extraction ([#​35696](https://github.com/nuxt/nuxt/pull/35696))
- **nuxt:** Mirror runtime route tree in generated typed-router types ([#​35788](https://github.com/nuxt/nuxt/pull/35788))
- **nuxt:** Warn when an imports preset `from` cannot be resolved ([#​35799](https://github.com/nuxt/nuxt/pull/35799))
- **kit:** Avoid mutating layer configs when resolving options ([#​35729](https://github.com/nuxt/nuxt/pull/35729))
- **nuxt:** Convert inline route rules exactly or drop with a warning ([#​35455](https://github.com/nuxt/nuxt/pull/35455))
- **nitro,nuxt,vite:** Dedupe and normalise global css links in dev ([#​35834](https://github.com/nuxt/nuxt/pull/35834))
- **vite:** Register template HMR plugin on dev servers ([929c6c138](https://github.com/nuxt/nuxt/commit/929c6c138))
- **nuxt:** Remove dev error overlay when error is cleared ([#​35821](https://github.com/nuxt/nuxt/pull/35821))
- **rspack,webpack:** Resolve bundled postcss defaults from builder ([#​35823](https://github.com/nuxt/nuxt/pull/35823))
- **schema:** Normalise slashes in `app.buildAssetsDir` ([#​35833](https://github.com/nuxt/nuxt/pull/35833))
- **nitro:** Bound island props and v-for to prevent unauthenticated DoS ([4e35ae9ba](https://github.com/nuxt/nuxt/commit/4e35ae9ba))
- **nitro:** Confine runtime payload cache to prerendering ([ac9b41a36](https://github.com/nuxt/nuxt/commit/ac9b41a36))
- **nuxt:** Case-fold route rule keys to match folded lookups ([ad624a75a](https://github.com/nuxt/nuxt/commit/ad624a75a))
- **nitro:** Require loopback peer for chrome devtools workspace endpoint ([0769c4f9b](https://github.com/nuxt/nuxt/commit/0769c4f9b))
- **nuxt:** Reject reserved `template` island prop under runtime compiler ([ee6c84633](https://github.com/nuxt/nuxt/commit/ee6c84633))
- **nuxt:** Reject top-level `as` prop for islands ([581651ff3](https://github.com/nuxt/nuxt/commit/581651ff3))
##### 💅 Refactors
- **nuxt:** Use tick based debounce for asyncData executes ([#​34151](https://github.com/nuxt/nuxt/pull/34151))
- **kit,nuxt:** Replace `semver` with `verkit` ([#​35713](https://github.com/nuxt/nuxt/pull/35713))
- **rspack,webpack:** Use DI model to split builders ([#​35751](https://github.com/nuxt/nuxt/pull/35751))
##### 📖 Documentation
- Add dev container setup guide ([#​35665](https://github.com/nuxt/nuxt/pull/35665))
- Fix dev container setup guide ([#​35666](https://github.com/nuxt/nuxt/pull/35666))
- Add explanation of 200.html and 404.html SPA fallbacks ([#​34483](https://github.com/nuxt/nuxt/pull/34483))
- Expand payload extraction documentation ([#​35648](https://github.com/nuxt/nuxt/pull/35648))
- Clarify NuxtLink componentName is the internal (devtools) name ([#​35658](https://github.com/nuxt/nuxt/pull/35658))
- Add example for components dir pattern option ([#​35663](https://github.com/nuxt/nuxt/pull/35663))
- Require a single root element ([#​35677](https://github.com/nuxt/nuxt/pull/35677))
- Add reason for why you should never import Vue app code in nitro code ([#​34481](https://github.com/nuxt/nuxt/pull/34481))
- Document disabling code-splitting with `codeSplitting: false` ([#​35683](https://github.com/nuxt/nuxt/pull/35683))
- Document nuxt-client caveat for non-SFC components ([#​35654](https://github.com/nuxt/nuxt/pull/35654))
- Clarify favicon does not use cdnURL by default ([#​35681](https://github.com/nuxt/nuxt/pull/35681))
- Standardize section order and headings across docs ([#​35685](https://github.com/nuxt/nuxt/pull/35685))
- Clarify `onPrehydrate` example comment ([#​35684](https://github.com/nuxt/nuxt/pull/35684))
- Add useId as a known limitation of nuxt island ([#​35693](https://github.com/nuxt/nuxt/pull/35693))
- Recommend status over pending in data fetching ([#​35694](https://github.com/nuxt/nuxt/pull/35694))
- Fill gaps in API minimalVersion badges after [#​34485](https://github.com/nuxt/nuxt/issues/34485) ([#​35708](https://github.com/nuxt/nuxt/pull/35708), [#​34485](https://github.com/nuxt/nuxt/issues/34485))
- Explain dynamic asset paths ([#​35695](https://github.com/nuxt/nuxt/pull/35695))
- Document `runtimeConfig` env var casting edge cases ([#​35709](https://github.com/nuxt/nuxt/pull/35709))
- Clarify module dependency resolution ([#​35718](https://github.com/nuxt/nuxt/pull/35718))
- Add more writing guidelines ([#​35662](https://github.com/nuxt/nuxt/pull/35662))
- Add note with alternatives to using remote layers ([#​35721](https://github.com/nuxt/nuxt/pull/35721))
- Use `nuxt` rather than `nuxi` ([8891e179c](https://github.com/nuxt/nuxt/commit/8891e179c))
- Document relative baseURL workarounds ([#​34004](https://github.com/nuxt/nuxt/pull/34004))
- Warn about `runtimeCompiler` security best practices ([449b63ab1](https://github.com/nuxt/nuxt/commit/449b63ab1))
- Warn about validating server component props ([2c981cb07](https://github.com/nuxt/nuxt/commit/2c981cb07))
##### 📦 Build
- **nitro:** Re-export type from augments to preserve module ([dac937675](https://github.com/nuxt/nuxt/commit/dac937675))
- **nuxt:** Remove `.ts` file extension from `runtime/` imports ([#​35689](https://github.com/nuxt/nuxt/pull/35689))
- **ui-templates:** Commit generated ui template files ([#​35770](https://github.com/nuxt/nuxt/pull/35770))
##### 🏡 Chore
- Add extension 🤦 ([d595fb3d4](https://github.com/nuxt/nuxt/commit/d595fb3d4))
- Move to pnpm catalogs ([#​35748](https://github.com/nuxt/nuxt/pull/35748))
- Update knip config, resolve issues, and run in ci ([#​35742](https://github.com/nuxt/nuxt/pull/35742))
- Ignore `@nuxt/telemetry` in knip ([9824d4f10](https://github.com/nuxt/nuxt/commit/9824d4f10))
- **ui-templates:** Pass config file path to unocss ([34e7a810d](https://github.com/nuxt/nuxt/commit/34e7a810d))
- Allow regenerating lockfile in release script ([c31389df3](https://github.com/nuxt/nuxt/commit/c31389df3))
- **nuxt:** Bump `@nuxt/devtools` to v3.3.1 ([#​35815](https://github.com/nuxt/nuxt/pull/35815))
- Ensure types are setup before unit tests ([784d8f700](https://github.com/nuxt/nuxt/commit/784d8f700))
- Simplify knip configuration ([#​35827](https://github.com/nuxt/nuxt/pull/35827))
##### ✅ Tests
- Reproduce duplicate CSS in shared chunks ([#​35649](https://github.com/nuxt/nuxt/pull/35649))
- Prepare fixtures automatically before fixture and e2e runs ([e8b3e6411](https://github.com/nuxt/nuxt/commit/e8b3e6411))
- Improve and refactor basic fixture ([#​35687](https://github.com/nuxt/nuxt/pull/35687))
- Slim down client-only, chunk-error and axis-independent suites ([#​35706](https://github.com/nuxt/nuxt/pull/35706))
- Do not run type checking when benchmarking nuxt build ([6355f3bc9](https://github.com/nuxt/nuxt/commit/6355f3bc9))
- **kit:** Scope loadNuxt temp dir so it doesn't delete sibling fixtures ([37301dd51](https://github.com/nuxt/nuxt/commit/37301dd51))
- Guard against transient undefined `_route` in gotoPath ([ca92d082b](https://github.com/nuxt/nuxt/commit/ca92d082b))
- Retry fixture prepare on transient ENOTEMPTY ([3a6b59f96](https://github.com/nuxt/nuxt/commit/3a6b59f96))
- Raise route-HMR polling timeout to reduce e2e flakiness ([01dc27b7e](https://github.com/nuxt/nuxt/commit/01dc27b7e))
- Update bundle size snapshot ([30d24817c](https://github.com/nuxt/nuxt/commit/30d24817c))
##### 🤖 CI
- Rebalance shards and drop non-vite windows fixtures ([#​35700](https://github.com/nuxt/nuxt/pull/35700))
- Warm windows dependency cache on main ([#​35730](https://github.com/nuxt/nuxt/pull/35730))
- Run knip in default and production modes ([#​35745](https://github.com/nuxt/nuxt/pull/35745))
- Run knip on pull requests ([d620aa972](https://github.com/nuxt/nuxt/commit/d620aa972))
- Prepare tests ([c7bf7f738](https://github.com/nuxt/nuxt/commit/c7bf7f738))
- Also prepare tests in `knip` job ([58f68bd64](https://github.com/nuxt/nuxt/commit/58f68bd64))
- Check internal docs links on pull requests and all links weekly ([#​35767](https://github.com/nuxt/nuxt/pull/35767))
##### ❤️ Contributors
- Daniel Roe ([@​danielroe](https://github.com/danielroe))
- Lars Kappert ([@​webpro](https://github.com/webpro))
- Matej Černý ([@​cernymatej](https://github.com/cernymatej))
- Anthony Fu ([@​antfu](https://github.com/antfu))
- Harlan Wilton ([@​harlan-zw](https://github.com/harlan-zw))
- Florian Heuberger ([@​Flo0806](https://github.com/Flo0806))
- Anoesj Sadraee ([@​Anoesj](https://github.com/Anoesj))
- Ryota Watanabe ([@​wattanx](https://github.com/wattanx))
- Alexander Lichter ([@​TheAlexLichter](https://github.com/TheAlexLichter))
- Nestor Vera ([@​hacknug](https://github.com/hacknug))
- Mateleo ([@​Mateleo](https://github.com/Mateleo))
- Kevin Deng ([@​sxzz](https://github.com/sxzz))
- Robin ([@​OrbisK](https://github.com/OrbisK))
- Bochkarev Ivan ([@​Ibochkarev](https://github.com/Ibochkarev))
- Quentin Macq ([@​quentinmcq](https://github.com/quentinmcq))
- Julien Huang ([@​huang-julien](https://github.com/huang-julien))
- Max ([@​onmax](https://github.com/onmax))
- Luke Nelson ([@​luc122c](https://github.com/luc122c))
- Darlan José Batista do Prado ([@​DarlanPrado](https://github.com/DarlanPrado))
- kealan ([@​KealanAU](https://github.com/KealanAU))
- Sushant ([@​sushantguri](https://github.com/sushantguri))
- raminjafary ([@​raminjafary](https://github.com/raminjafary))
- Aubakirov Asker ([@​Askerka00](https://github.com/Askerka00))
- lutejka ([@​lutejka](https://github.com/lutejka))
- Amulet Iris ([@​KazariAI](https://github.com/KazariAI))
- bdbch ([@​bdbch](https://github.com/bdbch))
- Elecmonkey ([@​elecmonkey](https://github.com/elecmonkey))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3OS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
4.5.0→4.5.1Release Notes
nuxt/nuxt (nuxt)
v4.5.1Compare Source
It fixes server-side RCE and unauthorized component instantiation via server island props, a route rule authorization bypass, server component DoS, cross-user payload disclosure on cached pages, and dev server path disclosure. Refreshing your lockfile also pulls in
@nuxt/devtools@3.3.1, which fixes a separate critical development-only RCE.If you already upgraded for the earlier route rule advisory (CVE-2026-53721), you still need this release: one of the fixes addresses a regression introduced by that fix.
If you use the
cache,swrorisrroute rules, purge any CDN or edge cache after upgrading; a leaked_payload.jsonmay already be cached upstream.Full details: Nuxt Security Patch Releases and GitHub Security Advisories.
👉 Changelog
compare changes
🔥 Performance
vue.optionsApiand disable it for v5+ (#35791)ssr: false(#35782)🩹 Fixes
useRoutein detached effect scope (#35659)nameorpathwhen reusing an existing page inpages:extend(#35661)useFetchmethod inference (#35671)force-cache(#35672).mtsfile extension in resolver (#33845)@unhead/vue/*from nuxt's dependency tree (#35690)$fetchwith nitro's$Fetch(#35704)vue-routerwhen there are island pages (#35739)h3that pins it to the version nuxt depends on (#35774)fromcannot be resolved (#35799)app.buildAssetsDir(#35833)templateisland prop under runtime compiler (ee6c84633)asprop for islands (581651ff3)💅 Refactors
semverwithverkit(#35713)📖 Documentation
codeSplitting: false(#35683)onPrehydrateexample comment (#35684)runtimeConfigenv var casting edge cases (#35709)nuxtrather thannuxi(8891e179c)runtimeCompilersecurity best practices (449b63ab1)📦 Build
.tsfile extension fromruntime/imports (#35689)🏡 Chore
@nuxt/telemetryin knip (9824d4f10)@nuxt/devtoolsto v3.3.1 (#35815)✅ Tests
_routein gotoPath (ca92d082b)🤖 CI
knipjob (58f68bd64)❤️ Contributors
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.