HTML Injection Vulnerability in Nuxt OG Image by Nuxt
CVE-2026-34405
6.1MEDIUM
What is CVE-2026-34405?
The Nuxt OG Image module, which generates Open Graph (OG) images using Vue templates in Nuxt applications, is vulnerable to HTML injection prior to version 6.2.5. This vulnerability allows attackers to inject arbitrary HTML attributes into the page body through the image generation component accessed via the URI: /_og/d/ or in older versions at /og-image/. Developers using versions prior to 6.2.5 should update to the latest release to mitigate this risk and ensure the integrity of their web applications.
Affected Version(s)
og-image < 6.2.5
