Description
Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fonts parameter through decodeOgImageParams. Attacker-controlled fonts[].path values flow through loadDefinedFonts into the font-assets/node.js binding, which performs a server-side fetch without validating the URL scheme, origin, resolved address, or redirects. This permits blind requests to loopback, private, link-local, cloud metadata, and other internal HTTP services, while differences in the outer response status and timing can reveal service reachability. Slow targets can also occupy OG image render workers for the configured fetch and render timeouts. This issue is fixed in version 6.7.0.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

Nuxt OG Image renders Open Graph images from Vue templates, and between versions 6.0.2 and 6.6.x it incorrectly allows unauthenticated access to the /_og/d/ route when security.strict is false and security.secret is empty. The fonts[].path parameter is base64url‑decoded and passed to a server‑side fetch without validating the URL scheme, origin, resolved address, or redirects, enabling blind SSRF. An attacker can cause requests to loopback interfaces, private networks, link‑local addresses, cloud metadata endpoints, and other internal HTTP services. Timing and status differences can reveal service reachability, and slow responses may tie up rendering workers for the configured fetch and render timeouts, potentially leading to denial of service.

Affected Systems

The vulnerability affects the Nuxt Modules OG Image package versions 6.0.2 through 6.6.x. It is fixed in version 6.7.0 and later.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain but the vulnerability exists in publicly accessible services. It is not listed in the CISA KEV catalog. Because authentication is not required and any party can issue a request to the vulnerable endpoint, the potential impact includes internal network reconnaissance, accidental exposure of sensitive services, and a possible denial‑of‑service if the target responds slowly or is repeatedly targeted.

Generated by OpenCVE AI on September 17, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade nuxt‑og‑image to version 6.7.0 or later.
  • If an immediate upgrade is not possible, configure the module with security.strict=true or set a non‑empty security.secret to disable the unauthenticated route.
  • Restrict the fonts[].path parameter by implementing a whitelist of allowed domains or URL schemes to prevent arbitrary server‑side requests.
  • Reduce the fetch and render timeout values to limit the impact of slow or malicious requests that could occupy rendering workers.

Generated by OpenCVE AI on September 17, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q8hw-4fvp-9rwv Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nuxt-modules
Nuxt-modules og-image
Vendors & Products Nuxt-modules
Nuxt-modules og-image

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fonts parameter through decodeOgImageParams. Attacker-controlled fonts[].path values flow through loadDefinedFonts into the font-assets/node.js binding, which performs a server-side fetch without validating the URL scheme, origin, resolved address, or redirects. This permits blind requests to loopback, private, link-local, cloud metadata, and other internal HTTP services, while differences in the outer response status and timing can reveal service reachability. Slow targets can also occupy OG image render workers for the configured fetch and render timeouts. This issue is fixed in version 6.7.0.
Title Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
Weaknesses CWE-1188
CWE-20
CWE-441
CWE-749
CWE-918
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N'}


Subscriptions

Nuxt-modules Og-image
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:15:46.383Z

Reserved: 2026-07-10T20:06:05.617Z

Link: CVE-2026-61793

cve-icon Vulnrichment

Updated: 2026-09-17T15:15:15.851Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:48.987

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-20

    Improper Input Validation

  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-749

    Exposed Dangerous Method or Function

  • CWE-918

    Server-Side Request Forgery (SSRF)