Template Injection Vulnerability in Nuxt Framework by Nuxt.js
CVE-2026-71320

8.1HIGH

Key Information:

Vendor

Nuxt

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71320?

An issue in Nuxt, an open-source web development framework for Vue.js, allows an attacker to inject a template key through the /__nuxt_island/ props into a dynamic component when the vue.runtimeCompiler option is enabled. This can lead to the execution of arbitrary templates in the Nitro process, posing a significant security risk. The vulnerability affects versions 3.4.0 to 3.21.10 and 4.5.1 and has been addressed in the latest releases.

Affected Version(s)

nuxt >= 4.0.0, < 4.5.1 < 4.0.0, 4.5.1

nuxt >= 3.4.0, < 3.21.10 < 3.4.0, 3.21.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.