<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:36:59.987397+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349207</id>
    <title>EUVD-2026-349207</title>
    <updated>2026-10-10T18:36:59.991047+00:00</updated>
    <content>EUVD-2026-349207</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71320</id>
    <title>fkie_cve-2026-71320</title>
    <updated>2026-10-10T18:36:59.991105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9473-5f9j-94wq</id>
    <title>GHSA-9473-5f9j-94wq — Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props</title>
    <updated>2026-10-10T18:36:59.991151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nuxt</p>
<p>## Impact</p>
<p>Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`&lt;component :is&gt;`, `resolveDynamicComponent`, or `h()`), an attacker can inject a `template` key into the island props to achieve server-side remote code execution in the Nitro process.</p>
<p>```json
{ "as": { "template": "&lt;attacker-controlled&gt;" } }
```</p>
<p>Vue's runtime template compiler compiles and executes the attacker-controlled `template` in the server process. The same primitive also works on the client side when the runtime compiler is active there, though the server-side path is the primary concern.</p>
<p>Some component libraries expose a polymorphic `as` / `asChild` prop that forwards its value into `&lt;component :is&gt;`; `@nuxt/ui` (via `reka-ui`) is a widely used example. An application is affected if such a component receives the attacker-controlled value, provided `vue.runtimeCompiler` is also enabled. Note this does not require the island author to explicitly forward a prop: island props that the island component does not declare fall through as attributes onto its single root element (standard Vue attribute inheritance), so an island whose root is a polymorphic component receives the attacker's `as` value implicitly. These libraries are not themselves vulnerable; they are noted only because they commonly provide the dynamic-comp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9473-5f9j-94wq"/>
  </entry>
</feed>
