THREAT OPS › Threat News › [GHSA] GHSA-9473-5f9j-94wq (high) — Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
[GHSA] GHSA-9473-5f9j-94wq (high) — Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9473-5f9j-94wq Severity: high CVE: CVE-2026-71320
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
## Impact
Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component reso
MITRE ATT&CK techniques
- Template InjectionT1221
Indicators of compromise
- CVE-2026-71320cve
Original source: https://github.com/advisories/GHSA-9473-5f9j-94wq