Template Injection Vulnerability in Nuxt Framework by Nuxt.js
CVE-2026-71320
8.1HIGH
What is CVE-2026-71320?
An issue in Nuxt, an open-source web development framework for Vue.js, allows an attacker to inject a template key through the /__nuxt_island/ props into a dynamic component when the vue.runtimeCompiler option is enabled. This can lead to the execution of arbitrary templates in the Nitro process, posing a significant security risk. The vulnerability affects versions 3.4.0 to 3.21.10 and 4.5.1 and has been addressed in the latest releases.
Affected Version(s)
nuxt >= 4.0.0, < 4.5.1 < 4.0.0, 4.5.1
nuxt >= 3.4.0, < 3.21.10 < 3.4.0, 3.21.10
