Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5.
References
| Link | Resource |
|---|---|
| https://github.com/nuxt-modules/og-image/security/advisories/GHSA-mg36-wvcr-m75h | Vendor Advisory Exploit |
Configurations
History
13 Apr 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nuxt-modules/og-image/security/advisories/GHSA-mg36-wvcr-m75h - Vendor Advisory, Exploit | |
| First Time |
Nuxt
Nuxt og Image |
|
| CPE | cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:* |
31 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 22:16
Updated : 2026-04-13 15:17
NVD link : CVE-2026-34405
Mitre link : CVE-2026-34405
CVE.ORG link : CVE-2026-34405
JSON object : View
Products Affected
nuxt
- og_image
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
