PT-2026-94364 · Npm · Nuxt Og Image
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
nuxt-og-image versions 6.0.2 through 6.6.x
Description
An unauthenticated Server-Side Request Forgery (SSRF) exists when the software is used with default security settings (
security.strict = false and security.secret = ""). The application exposes the / og/d/** endpoint, which processes a fonts parameter via the decodeOgImageParams() function. An attacker can provide a malicious URL in the fonts[].path variable, which is passed to the loadDefinedFonts() function and subsequently fetched by the server without validating the URL scheme, origin, or destination address.This allows blind requests to internal services, including loopback, private networks, and cloud metadata services (such as AWS IMDS). While the response body is not directly returned, a side-channel exists where the HTTP response status differs based on whether the internal target is reachable, allowing for internal port scanning and service enumeration. Additionally, requests to slow targets can exhaust render workers, leading to a denial of service.
Recommendations
Update nuxt-og-image to version 6.7.0.
As a temporary mitigation, set
security.strict to true and provide a non-empty string for security.secret in the configuration.Exploit
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nuxt Og Image