THREAT OPS › Threat News › [GHSA] GHSA-48hr-524c-v5w3 (medium) — Nuxt: Unauthorized Component Instantiation via Server Island Props
[GHSA] GHSA-48hr-524c-v5w3 (medium) — Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-48hr-524c-v5w3 Severity: medium CVE: CVE-2026-71318
Nuxt: Unauthorized Component Instantiation via Server Island Props
## Impact
Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can p
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-71318cve
Original source: https://github.com/advisories/GHSA-48hr-524c-v5w3