Nuxt Server Islands Vulnerability: Unauthorized Component Instantiation
- Severity
- HIGH
- Affected component
- nuxt (npm)
- Affected versions
- >= 4.0.0, < 4.5.1 or >= 3.1.0, < 3.21.10 or >= 4.0.0, < 4.4.7 or >= 3.18.0, < 3.21.7 or >= 4.4.7, < 4.5.1 or >= 3.21.7, < 3.21.10 or >= 4.0.0, < 4.4.7 or < 3.21.7 or >= 4.0.0, < 4.5.1 or >= 3.4.0, < 3.21.10 or >= 4.0.0, < 4.5.1 or >= 3.1.0, < 3.21.10 or >= 4.0.0, < 4.4.7 or < 3.21.7 or >= 3.4.3, < 3.21.6 or >= 4.0.0-alpha.1, < 4.4.6 or >= 3.1.0, < 3.21.6 or >= 4.0.0-alpha.1, < 4.4.6 or >= 3.4.0, < 3.4.3 or >= 3.11.0, < 3.21.6 or >= 4.0.0-alpha.1, < 4.4.6 or >= 4.0.0, < 4.5.1 or >= 3.1.0, < 3.21.10 or >= 4.4.7, < 4.5.1 or >= 3.21.7, < 3.21.10 or >= 3.0.0, < 3.16.0 or >= 4.0.0, < 4.4.7 or < 3.21.7 or >= 4.0.0, < 4.4.7 or >= 3.11.0, < 3.21.7 or >= 3.6.0, < 3.19.0 or >= 4.0.0, < 4.1.0 or >= 4.0.0-alpha.1, < 4.4.7 or >= 3.4.0, < 3.12.4 or < 3.12.4 or >= 4.4.0, < 4.5.1
- Patched version
- Not yet available
An early warning has been issued for a high severity vulnerability in Nuxt server islands that reportedly allows unauthorized instantiation of globally-registered Vue components or native HTML elements.
What happened
The vulnerability, tracked as GHSA-48HR-524C-V5W3, is under investigation and has not yet been exploited in the wild. It affects Nuxt versions >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.0.0, < 4.4.7, >= 3.18.0, < 3.21.7, >= 4.4.7, < 4.5.1, >= 3.21.7, < 3.21.10, >= 4.0.0, < 4.4.7, < 3.21.7, >= 3.4.0, < 3.21.10, >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.0.0, < 4.4.7, < 3.21.7, >= 3.4.3, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 3.1.0, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 3.4.0, < 3.4.3, >= 3.11.0, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.4.7, < 4.5.1, >= 3.21.7, < 3.21.10, >= 3.0.0, < 3.16.0, >= 4.0.0, < 4.4.7, < 3.21.7, >= 4.0.0, < 4.4.7, >= 3.11.0, < 3.21.7, >= 3.6.0, < 3.19.0, >= 4.0.0, < 4.1.0, >= 4.0.0-alpha.1, < 4.4.7, >= 3.4.0, < 3.12.4, < 3.12.4, >= 4.4.0, < 4.5.1.
The issue arises from the way Nuxt server islands accept props via the `/__nuxt_island/` endpoint, which allows an attacker to instantiate any globally-registered Vue component or native HTML element by passing a plain string value.
To assess your exposure, check if your project uses Nuxt within the affected version ranges. If so, review how props are passed to server islands and ensure they are strictly controlled and validated.
What to do about it
- Avoid using server islands if possible.
- Ensure that props passed to server islands are strictly controlled and validated.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
- Consult the primary sources for the most current information on affected versions and recommended actions.
How 0Day would have caught this
nuxt is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using Nuxt within the version ranges >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.0.0, < 4.4.7, >= 3.18.0, < 3.21.7, >= 4.4.7, < 4.5.1, >= 3.21.7, < 3.21.10, >= 4.0.0, < 4.4.7, < 3.21.7, >= 3.4.0, < 3.21.10, >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.0.0, < 4.4.7, < 3.21.7, >= 3.4.3, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 3.1.0, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 3.4.0, < 3.4.3, >= 3.11.0, < 3.21.6, >= 4.0.0-alpha.1, < 4.4.6, >= 4.0.0, < 4.5.1, >= 3.1.0, < 3.21.10, >= 4.4.7, < 4.5.1, >= 3.21.7, < 3.21.10, >= 3.0.0, < 3.16.0, >= 4.0.0, < 4.4.7, < 3.21.7, >= 4.0.0, < 4.4.7, >= 3.11.0, < 3.21.7, >= 3.6.0, < 3.19.0, >= 4.0.0, < 4.1.0, >= 4.0.0-alpha.1, < 4.4.7, >= 3.4.0, < 3.12.4, < 3.12.4, >= 4.4.0, < 4.5.1.
What should I do right now?
Avoid using server islands if possible. If you must use them, ensure that props passed to server islands are strictly controlled and validated. Monitor the primary sources for updates on the vulnerability and any official fixes.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.
How can I validate props passed to server islands?
Consult the Nuxt documentation and security advisories for best practices on validating props. Ensure that only expected and safe values are accepted.