How to use this reference
Nuxt identifies 4.5.1 and 3.21.10 as patched for the common implicit-inheritance path. Explicit untrusted component selection remains application responsibility. Editorial lesson: define both accepted data and allowed interpretation at component boundaries; map external choices to a closed set of trusted components rather than treating strings as authority.
Before reading
- Server-rendered applications and framework composition
- Trust-boundary modeling and application authorization
Context and limits
- CVE-2026-71318. Requires active server islands and a dynamic-component consumer; installing a UI library alone is insufficient. Runtime template compilation is not required.
- Affected ranges: 3.1.0 through below 3.21.10, and 4.0.0 through below 4.5.1. Nuxt 2 is excluded. danielroe published the advisory.
- Patch-release dates were not established. Data exposure beyond unintended rendering depends on reachable components and is not demonstrated here.
- No bounty or production compromise is established. Learning prerequisites and generalized defensive reasoning are editorial.
Sources and provenance
- Unauthorized Component Instantiation via Server Island Props in Nuxt Nuxt · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.