THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-48hr-524c-v5w3 (medium) — Nuxt: Unauthorized Component Instantiation via Server Island Props

[GHSA] GHSA-48hr-524c-v5w3 (medium) — Nuxt: Unauthorized Component Instantiation via Server Island Props

medgithub_advisoriesPublished 2026-08-05

GHSA-48hr-524c-v5w3 Severity: medium CVE: CVE-2026-71318

Nuxt: Unauthorized Component Instantiation via Server Island Props

## Impact

Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can p

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-48hr-524c-v5w3