Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g8wj-3cr3-6w7v | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning |
Mon, 15 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt nuxt\/nitro-server
|
|
| CPEs | cpe:2.3:a:nuxt:nuxt:*:*:*:*:*:*:*:* cpe:2.3:a:nuxt:nuxt\/nitro-server:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Nuxt nuxt\/nitro-server
|
|
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt
Nuxt nuxt |
|
| Vendors & Products |
Nuxt
Nuxt nuxt |
Fri, 12 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_island/* endpoint accepts attacker-controlled props query/body parameters and renders any island component without verifying that the URL-resident hash (<Name>_<hashId>.json) was actually issued for those inputs by <NuxtIsland>. The hash is computed and embedded client-side but never validated server-side, so the same path can return materially different responses depending on the query. This issue has been patched in versions 3.21.6 and 4.4.6. | |
| Title | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning | |
| Weaknesses | CWE-349 CWE-444 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T20:54:39.647Z
Reserved: 2026-05-13T18:37:30.990Z
Link: CVE-2026-46342
Updated: 2026-06-12T14:38:07.488Z
Status : Analyzed
Published: 2026-06-12T14:16:31.590
Modified: 2026-06-15T18:09:23.353
Link: CVE-2026-46342
No data.
OpenCVE Enrichment
Updated: 2026-06-12T15:00:09Z
Github GHSA