nuxt-og-image is vulnerable to Server-Side Request Forgery (SSRF)
37
Low Risk
The module resolves remote image sources when rendering Open Graph output. After baseline URL filtering shipped for direct requests, follow-on HTTP flows could still expose gaps around redirect chains and certain IPv6-shaped targets such that an allowed first hop could pivot toward unintended destinations during fetching. The maintenance release validates redirects stepwise alongside broader address handling and tightens renderer lifecycle limits so hook and WASM-backed rendering cannot stall indefinitely when inputs abuse slow paths.
You are affected if you are using a version that falls within the vulnerable range.
nuxt-og-image is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.2.5 - 6.4.8.
Upgrade the nuxt-og-image library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant