PT-2026-29371 · Unknown · Nuxt Og Image
Dmitry Prokhorov
·
Published
2026-03-26
·
Updated
2026-04-01
·
CVE-2026-34405
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nuxt OG Image versions prior to 6.2.5
Description
The Nuxt OG Image package contains a flaw in the image-generation component accessible via the API endpoint
/ og/d/ (and /og-image/ in older versions). This issue allows for the injection of arbitrary attributes into the HTML page body through manipulation of GET parameters. Specifically, the vulnerability arises from incorrect parsing of these parameters, leading to potential HTML and JavaScript code injection. The onmouseover and autofocus parameters can be exploited to inject attributes directly into the generated HTML page.Recommendations
Versions prior to 6.2.5: Upgrade to version 6.2.5 or later to address the vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuxt Og Image