Impact
Nuxt OG Image renders Open Graph images from Vue templates, and between versions 6.0.2 and 6.6.x it incorrectly allows unauthenticated access to the /_og/d/ route when security.strict is false and security.secret is empty. The fonts[].path parameter is base64url‑decoded and passed to a server‑side fetch without validating the URL scheme, origin, resolved address, or redirects, enabling blind SSRF. An attacker can cause requests to loopback interfaces, private networks, link‑local addresses, cloud metadata endpoints, and other internal HTTP services. Timing and status differences can reveal service reachability, and slow responses may tie up rendering workers for the configured fetch and render timeouts, potentially leading to denial of service.
Affected Systems
The vulnerability affects the Nuxt Modules OG Image package versions 6.0.2 through 6.6.x. It is fixed in version 6.7.0 and later.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain but the vulnerability exists in publicly accessible services. It is not listed in the CISA KEV catalog. Because authentication is not required and any party can issue a request to the vulnerable endpoint, the potential impact includes internal network reconnaissance, accidental exposure of sensitive services, and a possible denial‑of‑service if the target responds slowly or is repeatedly targeted.
OpenCVE Enrichment
Github GHSA