1. Nuxt.js Dev Toolchain Pins Defu Dependency to Patch High-Severity Prototype Pollution (CVE-2026-35209)
A high-severity prototype pollution vulnerability (CVE-2026-35209 / GHSA-737v-mqg7-c878) in the `defu` library has triggered a forced dependency override within the Nuxt.js framework's development toolchain. The vulnerability, present in `defu` version 6.1.4, was discovered in a transitive dependency used by `@hey-api/...