<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 05:23:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348962</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348962</link>
      <description>EUVD-2026-348962</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348962</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71318</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71318</link>
      <description>&lt;p&gt;Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through &amp;lt;component :is&amp;gt;, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through &amp;lt;component :is&amp;gt;, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71318</guid>
    </item>
    <item>
      <title>GHSA-48hr-524c-v5w3 — Nuxt: Unauthorized Component Instantiation via Server Island Props</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-48hr-524c-v5w3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue&amp;#39;s dynamic component resolution (`&amp;lt;component :is&amp;gt;`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (rather than a component definition) to instantiate any globally-registered Vue component or any native HTML element.&lt;/p&gt;
&lt;p&gt;For example:
```json
{ &amp;#34;as&amp;#34;: &amp;#34;SomeGlobalComponent&amp;#34; }
```&lt;/p&gt;
&lt;p&gt;...resolves and renders `SomeGlobalComponent` if it is globally registered, even though the attacker should only be able to drive props for the island&amp;#39;s declared component. Similarly, `{ &amp;#34;as&amp;#34;: &amp;#34;iframe&amp;#34; }` renders an `&amp;lt;iframe&amp;gt;` element.&lt;/p&gt;
&lt;p&gt;Unlike the primary RCE vector (GHSA-9473-5f9j-94wq), this does **not** require `vue.runtimeCompiler` to be enabled. A plain string prop is sufficient to trigger component resolution. The `template`/`render` key guard that addresses the RCE vector does not block plain string values.&lt;/p&gt;
&lt;p&gt;Some component libraries expose a polymorphic `as` / `asChild` prop that forwards its value into `&amp;lt;component :is&amp;gt;`; `@nuxt/ui` (via `reka-ui`) is a widely used example. An application is affected if such a component receives the attacker-controlled value inside a server island. Note this does not require explicit prop forwarding: island props the island component does not declare fall through as attributes onto its single root element, so an island whose root is a `reka-ui` / `@nuxt/ui` component…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue&amp;#39;s dynamic component resolution (`&amp;lt;component :is&amp;gt;`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (rather than a component definition) to instantiate any globally-registered Vue component or any native HTML element.&lt;/p&gt;
&lt;p&gt;For example:
```json
{ &amp;#34;as&amp;#34;: &amp;#34;SomeGlobalComponent&amp;#34; }
```&lt;/p&gt;
&lt;p&gt;...resolves and renders `SomeGlobalComponent` if it is globally registered, even though the attacker should only be able to drive props for the island&amp;#39;s declared component. Similarly, `{ &amp;#34;as&amp;#34;: &amp;#34;iframe&amp;#34; }` renders an `&amp;lt;iframe&amp;gt;` element.&lt;/p&gt;
&lt;p&gt;Unlike the primary RCE vector (GHSA-9473-5f9j-94wq), this does **not** require `vue.runtimeCompiler` to be enabled. A plain string prop is sufficient to trigger component resolution. The `template`/`render` key guard that addresses the RCE vector does not block plain string values.&lt;/p&gt;
&lt;p&gt;Some component libraries expose a polymorphic `as` / `asChild` prop that forwards its value into `&amp;lt;component :is&amp;gt;`; `@nuxt/ui` (via `reka-ui`) is a widely used example. An application is affected if such a component receives the attacker-controlled value inside a server island. Note this does not require explicit prop forwarding: island props the island component does not declare fall through as attributes onto its single root element, so an island whose root is a `reka-ui` / `@nuxt/ui` component…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-48hr-524c-v5w3</guid>
    </item>
  </channel>
</rss>
