What is CVE-2026-71320?
In Nuxt framework, when `vue.runtimeCompiler: true` is enabled, a template key injection via `/__nuxt_island/` props is possible, leading to arbitrary template execution in the Nitro process. This affects versions 3.4.0 through 3.21.10 and 4.5.1. Immediate upgrade from the affected versions is recommended.
Azərbaycanca: Nuxt freymvorkunda `vue.runtimeCompiler: true` aktiv olduqda, `/__nuxt_island/` üzərindən şablon açarı inyeksiyası mümkündür. Bu, Nitro prosesində ixtiyari şablon icrasına səbəb olur, versiyalar 3.4.0-3.21.10 və 4.5.1-i əhatə edir. Təsirə məruz qalan versiyalardan təcili yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which configuration must be enabled to exploit CVE-2026-71320 in Nuxt?
The `vue.runtimeCompiler: true` option must be enabled for the vulnerability to be exploited.
Which Nuxt versions are affected by CVE-2026-71320?
Versions 3.4.0 through 3.21.10 and version 4.5.1 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.