Executive brief
Nuxt is a popular web development framework. A vulnerability in how it handles 'island' components—parts of a page that render independently—could allow an attacker to manipulate the content displayed to other users. If the application is behind a caching service like a CDN, an attacker could trick the system into saving a malicious version of a page component, potentially leading to the theft of user data or the execution of unauthorized scripts (XSS).
Technical details
The /__nuxt_island/* endpoint accepts attacker-controlled props via query or body parameters but fails to verify the URL-resident hash (<Name>_<hashId>.json) on the server side. Because the hash is only computed client-side, an attacker can provide arbitrary props for a given path. In environments where a CDN or reverse proxy caches these responses based on the URL path alone (ignoring query strings), an attacker can poison the cache with malicious props. If these props flow into unsafe HTML sinks like v-html, this results in stored XSS. The issue is fixed in Nuxt 3.21.6 and 4.4.6 by re-validating the hashId against the provided props on the server.
Affected products
- Nuxt Nuxt 3.1.0 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
- Nuxt @nuxt/nitro-server 3.20.0 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
Timeline
- 2026-05-13: patched: Fix merged in GitHub pull request #35077
- 2026-05-18: advisory: GitHub Security Advisory GHSA-g8wj-3cr3-6w7v published
- 2026-06-12: disclosed: CVE-2026-46342 published to NVD