Medium · 4.6 Node.js & npm GHSA-q8hw-4fvp-9rwv CVE-2026-61793
Unauthenticated SSRF in Nuxt OG Image via fonts[].path Parameter (CVE-2026-61793)
Nuxt OG Image before version 6.7.0 exposes an unauthenticated route that can be abused to make the server perform blind HTTP requests to internal services, including loopback, private, and cloud metadata addresses, when the package's documented default configuration is used.
AI summary
A vulnerability has been disclosed in nuxt-og-image, an npm package used to generate Open Graph images from Vue templates in Nuxt applications. The issue allows unauthenticated attackers to coerce the server into making outbound HTTP requests to internal or otherwise restricted network locations by supplying a crafted font path value. This is tracked as CVE-2026-61793 and GHSA-q8hw-4fvp-9rwv, and is fixed in version 6.7.0.
What happened
nuxt-og-image exposes a route (/_og/d/**) that, under the package's documented default settings, is reachable without authentication. The route accepts a base64url-encoded 'fonts' parameter that is decoded and passed through to a font-loading mechanism. Attacker-supplied values in fonts[].path are forwarded to a server-side fetch operation that does not validate the URL scheme, origin, resolved network address, or any redirects involved.
Technical cause
The vulnerability stems from improper input validation (CWE-20). Specifically, the decodeOgImageParams function base64url-decodes the fonts parameter, and the resulting fonts[].path values flow unchecked into loadDefinedFonts and then into a font-assets Node.js binding that performs the actual HTTP fetch. Because the scheme, destination, and redirect targets of this fetch are not validated, an attacker can direct the server to make requests to arbitrary internal or external network locations.
Why it matters
This flaw permits blind SSRF requests to loopback addresses, private network ranges, link-local addresses, and cloud metadata endpoints. Even though the response body itself is not necessarily returned to the attacker, differences in response status and response timing can reveal whether an internal service is reachable, enabling network reconnaissance. Additionally, requests to slow or unresponsive targets can occupy OG image rendering workers for the duration of the configured fetch and render timeouts, which could degrade service availability.
Who is affected
Applications using nuxt-og-image are affected when the package's documented default configuration is in use, specifically when security.strict is set to false and security.secret is left as an empty string. Under these defaults, the vulnerable /_og/d/** route is reachable without authentication.
Affected versions
Versions of nuxt-og-image from 6.0.2 up to, but not including, 6.7.0 are affected.
Fixes and mitigation
The issue is fixed in nuxt-og-image version 6.7.0. Site owners and developers using nuxt-og-image should upgrade to this version.
Recommended action
Upgrade nuxt-og-image to version 6.7.0 as soon as practical. If an immediate upgrade is not possible, review your security.strict and security.secret configuration values, since the vulnerability as described relies on the documented default settings (security.strict = false and security.secret = "") to leave the affected route unauthenticated.
PatchBriefing score
4.6 / 10 · Medium
Official CVSS: 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
This advisory carries a PatchBriefing score of 4.6, based on a CVSS v4.0 base score of 6.9. Contributing factors include the unauthenticated, remotely reachable nature of the flaw and the absence of required user interaction, both of which increase ease of exploitation. The score is moderated by the fact that there is no known exploitation in the wild, no public exploit code, and a fix is already available. EPSS data indicates a low predicted likelihood of near-term exploitation (score around 0.5%, percentile around 40%).
Affected versions
- nuxt-og-image >= 6.0.2, < 6.7.0
- vulnerable
- ≥ 6.7.0
- patched
Reported fixes
The issue is fixed in nuxt-og-image version 6.7.0. Site owners and developers using nuxt-og-image should upgrade to this version.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email