Executive brief
Nuxt is a popular framework used to build websites and web applications. A security flaw was found where certain server-side pages could bypass intended security checks (middleware), such as login requirements. This means an unauthorized person could potentially view restricted content by accessing a specific internal web address used by the framework. This issue primarily affects sites using the 'component islands' feature with server-only page files.
Technical details
A vulnerability exists in Nuxt's 'Server Islands' feature (experimental.componentIslands) where .server.vue files located in the pages/ directory are exposed via the /__nuxt_island/:name endpoint. When accessed through this endpoint, the SSR renderer bypasses the Vue Router instantiation, causing route middleware (defined via definePageMeta) to be skipped. An attacker can exploit this by directly requesting the island endpoint for a specific route, bypassing authentication or authorization checks that rely solely on middleware. The issue is resolved in versions 3.21.6 and 4.4.6 by ensuring the router plugin executes middleware for page-based islands and validating that the requested island matches the resolved route.
Affected products
- Nuxt Nuxt 3.11.0 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
- Nuxt @nuxt/nitro-server 3.20.0 to < 3.21.6, 4.0.0-alpha.1 to < 4.4.6
Timeline
- 2026-05-17: other: Fix PR submitted to GitHub
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD