PT-2026-94364 · Npm · Nuxt Og Image

·

CVE-2026-61793

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions nuxt-og-image versions 6.0.2 through 6.6.x
Description An unauthenticated Server-Side Request Forgery (SSRF) exists when the software is used with default security settings (security.strict = false and security.secret = ""). The application exposes the / og/d/** endpoint, which processes a fonts parameter via the decodeOgImageParams() function. An attacker can provide a malicious URL in the fonts[].path variable, which is passed to the loadDefinedFonts() function and subsequently fetched by the server without validating the URL scheme, origin, or destination address.
This allows blind requests to internal services, including loopback, private networks, and cloud metadata services (such as AWS IMDS). While the response body is not directly returned, a side-channel exists where the HTTP response status differs based on whether the internal target is reachable, allowing for internal port scanning and service enumeration. Additionally, requests to slow targets can exhaust render workers, leading to a denial of service.
Recommendations Update nuxt-og-image to version 6.7.0. As a temporary mitigation, set security.strict to true and provide a non-empty string for security.secret in the configuration.

Exploit

Fix

SSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-61793
GHSA-Q8HW-4FVP-9RWV

Affected Products

Nuxt Og Image