<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T10:55:34.148829+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348962</id>
    <title>EUVD-2026-348962</title>
    <updated>2026-10-10T10:55:34.194296+00:00</updated>
    <content>EUVD-2026-348962</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71318</id>
    <title>fkie_cve-2026-71318</title>
    <updated>2026-10-10T10:55:34.194334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through &lt;component :is&gt;, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-48hr-524c-v5w3</id>
    <title>GHSA-48hr-524c-v5w3 — Nuxt: Unauthorized Component Instantiation via Server Island Props</title>
    <updated>2026-10-10T10:55:34.194369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nuxt</p>
<p>## Impact</p>
<p>Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`&lt;component :is&gt;`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (rather than a component definition) to instantiate any globally-registered Vue component or any native HTML element.</p>
<p>For example:
```json
{ "as": "SomeGlobalComponent" }
```</p>
<p>...resolves and renders `SomeGlobalComponent` if it is globally registered, even though the attacker should only be able to drive props for the island's declared component. Similarly, `{ "as": "iframe" }` renders an `&lt;iframe&gt;` element.</p>
<p>Unlike the primary RCE vector (GHSA-9473-5f9j-94wq), this does **not** require `vue.runtimeCompiler` to be enabled. A plain string prop is sufficient to trigger component resolution. The `template`/`render` key guard that addresses the RCE vector does not block plain string values.</p>
<p>Some component libraries expose a polymorphic `as` / `asChild` prop that forwards its value into `&lt;component :is&gt;`; `@nuxt/ui` (via `reka-ui`) is a widely used example. An application is affected if such a component receives the attacker-controlled value inside a server island. Note this does not require explicit prop forwarding: island props the island component does not declare fall through as attributes onto its single root element, so an island whose root is a `reka-ui` / `@nuxt/ui` component…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-48hr-524c-v5w3"/>
  </entry>
</feed>
