Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
Vulnerability Description
Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.2.5 to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies, March 2026) is incomplete. It has an incomplete IPv6 prefix list and is missing redirect re-validation. This vulnerability is fixed in 6.4.9.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
nuxt-og-image 代码问题漏洞
Vulnerability Description
nuxt-og-image是Nuxt Modules开源的一个为Nuxt应用生成社交媒体预览图的工具。 nuxt-og-image 6.2.5至6.4.9之前版本存在代码问题漏洞,该漏洞源于isBlockedUrl()黑名单不完整,可能导致绕过安全限制。
CVSS Information
N/A
Vulnerability Type
N/A