Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mg36-wvcr-m75h | Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes |
Mon, 13 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt
Nuxt og Image |
|
| CPEs | cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nuxt
Nuxt og Image |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt-modules
Nuxt-modules og-image |
|
| Vendors & Products |
Nuxt-modules
Nuxt-modules og-image |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5. | |
| Title | Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T18:43:23.097Z
Reserved: 2026-03-27T13:45:29.620Z
Link: CVE-2026-34405
Updated: 2026-04-01T18:43:18.343Z
Status : Analyzed
Published: 2026-03-31T22:16:18.813
Modified: 2026-04-13T15:17:23.693
Link: CVE-2026-34405
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:42:13Z
Github GHSA