Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.6 Node.js & npm GHSA-q8hw-4fvp-9rwv CVE-2026-61793

Unauthenticated SSRF in Nuxt OG Image via fonts[].path Parameter (CVE-2026-61793)

Nuxt OG Image before version 6.7.0 exposes an unauthenticated route that can be abused to make the server perform blind HTTP requests to internal services, including loopback, private, and cloud metadata addresses, when the package's documented default configuration is used.

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

A vulnerability has been disclosed in nuxt-og-image, an npm package used to generate Open Graph images from Vue templates in Nuxt applications. The issue allows unauthenticated attackers to coerce the server into making outbound HTTP requests to internal or otherwise restricted network locations by supplying a crafted font path value. This is tracked as CVE-2026-61793 and GHSA-q8hw-4fvp-9rwv, and is fixed in version 6.7.0.

What happened

nuxt-og-image exposes a route (/_og/d/**) that, under the package's documented default settings, is reachable without authentication. The route accepts a base64url-encoded 'fonts' parameter that is decoded and passed through to a font-loading mechanism. Attacker-supplied values in fonts[].path are forwarded to a server-side fetch operation that does not validate the URL scheme, origin, resolved network address, or any redirects involved.

Technical cause

The vulnerability stems from improper input validation (CWE-20). Specifically, the decodeOgImageParams function base64url-decodes the fonts parameter, and the resulting fonts[].path values flow unchecked into loadDefinedFonts and then into a font-assets Node.js binding that performs the actual HTTP fetch. Because the scheme, destination, and redirect targets of this fetch are not validated, an attacker can direct the server to make requests to arbitrary internal or external network locations.

Why it matters

This flaw permits blind SSRF requests to loopback addresses, private network ranges, link-local addresses, and cloud metadata endpoints. Even though the response body itself is not necessarily returned to the attacker, differences in response status and response timing can reveal whether an internal service is reachable, enabling network reconnaissance. Additionally, requests to slow or unresponsive targets can occupy OG image rendering workers for the duration of the configured fetch and render timeouts, which could degrade service availability.

Who is affected

Applications using nuxt-og-image are affected when the package's documented default configuration is in use, specifically when security.strict is set to false and security.secret is left as an empty string. Under these defaults, the vulnerable /_og/d/** route is reachable without authentication.

Affected versions

Versions of nuxt-og-image from 6.0.2 up to, but not including, 6.7.0 are affected.

Fixes and mitigation

The issue is fixed in nuxt-og-image version 6.7.0. Site owners and developers using nuxt-og-image should upgrade to this version.

Recommended action

Upgrade nuxt-og-image to version 6.7.0 as soon as practical. If an immediate upgrade is not possible, review your security.strict and security.secret configuration values, since the vulnerability as described relies on the documented default settings (security.strict = false and security.secret = "") to leave the affected route unauthenticated.

PatchBriefing score

4.6 / 10 · Medium

Official CVSS: 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This advisory carries a PatchBriefing score of 4.6, based on a CVSS v4.0 base score of 6.9. Contributing factors include the unauthenticated, remotely reachable nature of the flaw and the absence of required user interaction, both of which increase ease of exploitation. The score is moderated by the fact that there is no known exploitation in the wild, no public exploit code, and a fix is already available. EPSS data indicates a low predicted likelihood of near-term exploitation (score around 0.5%, percentile around 40%).

Affected versions

nuxt-og-image >= 6.0.2, < 6.7.0
vulnerable
≥ 6.7.0
patched

Reported fixes

The issue is fixed in nuxt-og-image version 6.7.0. Site owners and developers using nuxt-og-image should upgrade to this version.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Unauthenticated SSRF in Nuxt OG Image via fonts[].path Parameter (CVE-2026-61793)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email