vulns.co
/
GKData.io MCP

Nuxt · 1 min read

Nuxt: island data must not acquire component-selection authority

The maintainer describes request-controlled island data reaching dynamic component selection through attribute inheritance. This permits unintended registered-component or native-element rendering. The boundary fails when input intended to configure an approved component instead chooses what component runs. The advisory expressly excludes arbitrary JavaScript execution through this vector.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Nuxt identifies 4.5.1 and 3.21.10 as patched for the common implicit-inheritance path. Explicit untrusted component selection remains application responsibility. Editorial lesson: define both accepted data and allowed interpretation at component boundaries; map external choices to a closed set of trusted components rather than treating strings as authority.

Before reading

  • Server-rendered applications and framework composition
  • Trust-boundary modeling and application authorization

Context and limits

  • CVE-2026-71318. Requires active server islands and a dynamic-component consumer; installing a UI library alone is insufficient. Runtime template compilation is not required.
  • Affected ranges: 3.1.0 through below 3.21.10, and 4.0.0 through below 4.5.1. Nuxt 2 is excluded. danielroe published the advisory.
  • Patch-release dates were not established. Data exposure beyond unintended rendering depends on reachable components and is not demonstrated here.
  • No bounty or production compromise is established. Learning prerequisites and generalized defensive reasoning are editorial.

Sources and provenance

  1. Unauthorized Component Instantiation via Server Island Props in Nuxt Nuxt · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software