Record summary

CVE-2026-71318 has a selected CVSS score of 4.8 (medium).

Description

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 4.0.0, < 4.5.1affected
>= 3.1.0, < 3.21.10affected
GitHub Advisory4.0.0 to < 4.5.1 · Fixed in 4.5.1affected
3.1.0 to < 3.21.10 · Fixed in 3.21.10affected

References

4