github.com
https://github.com/nuxt/nuxt CVE-2026-71318
MEDIUM
Nuxt: Unauthorized Component Instantiation via Server Island Props
Record summary
CVE-2026-71318 has a selected CVSS score of 4.8 (medium).
Description
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 4.0.0, < 4.5.1 | affected | |
| >= 3.1.0, < 3.21.10 | affected | ||
| GitHub Advisory | 4.0.0 to < 4.5.1 · Fixed in 4.5.1 | affected | |
| 3.1.0 to < 3.21.10 · Fixed in 3.21.10 | affected |
References
4github.com
https://github.com/nuxt/nuxt/releases/tag/v3.21.10 github.com
https://github.com/nuxt/nuxt/releases/tag/v4.5.1 github.comConfirmation
https://github.com/nuxt/nuxt/security/advisories/GHSA-48hr-524c-v5w3