Description
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mg36-wvcr-m75h | Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes |
References
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5. | |
| Title | Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T18:43:23.097Z
Reserved: 2026-03-27T13:45:29.620Z
Link: CVE-2026-34405
Updated: 2026-04-01T18:43:18.343Z
Status : Awaiting Analysis
Published: 2026-03-31T22:16:18.813
Modified: 2026-04-01T14:23:37.727
Link: CVE-2026-34405
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA