Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 22:17
Updated : 2026-09-08 20:51
NVD link : CVE-2026-71320
Mitre link : CVE-2026-71320
CVE.ORG link : CVE-2026-71320
JSON object : View
Products Affected
No product.
