CVE-2026-71318 - Nuxt: Unauthorized Component Instantiation via Server Island Props
CVE ID :CVE-2026-71318
Published : Aug. 5, 2026, 10:17 p.m. | 38 minutes ago
Description :Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 5, 2026, 10:17 p.m. | 38 minutes ago
Description :Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...