PT-2026-29371 · Unknown · Nuxt Og Image

Dmitry Prokhorov

·

Published

2026-03-26

·

Updated

2026-04-01

·

CVE-2026-34405

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nuxt OG Image versions prior to 6.2.5
Description The Nuxt OG Image package contains a flaw in the image-generation component accessible via the API endpoint / og/d/ (and /og-image/ in older versions). This issue allows for the injection of arbitrary attributes into the HTML page body through manipulation of GET parameters. Specifically, the vulnerability arises from incorrect parsing of these parameters, leading to potential HTML and JavaScript code injection. The onmouseover and autofocus parameters can be exploited to inject attributes directly into the generated HTML page.
Recommendations Versions prior to 6.2.5: Upgrade to version 6.2.5 or later to address the vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05816
CVE-2026-34405
GHSA-MG36-WVCR-M75H

Affected Products

Nuxt Og Image