Intel

AIKIDO-2026-10732

nuxt-og-image is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-c2rm-g55x-8hr5 Published May 4, 2026

37

Low Risk

This Affects:

JSnuxt-og-image
6.2.5 - 6.4.8
Fixed in 6.4.9
Are you affected? Scan for Free

TL;DR

The module resolves remote image sources when rendering Open Graph output. After baseline URL filtering shipped for direct requests, follow-on HTTP flows could still expose gaps around redirect chains and certain IPv6-shaped targets such that an allowed first hop could pivot toward unintended destinations during fetching. The maintenance release validates redirects stepwise alongside broader address handling and tightens renderer lifecycle limits so hook and WASM-backed rendering cannot stall indefinitely when inputs abuse slow paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nuxt-og-image is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.2.5 - 6.4.8.

How to fix this

Upgrade the nuxt-og-image library to the patch version.