CVE-2026-61793 with a CVSS score of 6.9 is a server-side request forgery (SSRF) vulnerability in nuxt-og-image that allows unauthenticated remote attackers to make arbitrary HTTP requests from the Nuxt server by supplying attacker-controlled font URLs through the /_og/d/** endpoint. The vulnerable implementation lacks URL validation and permits requests to internal services including loopback addresses private networks cloud metadata endpoints and internal administrative interfaces. A response-status side channel can also allow attackers to identify reachable internal services and open ports.
We recommend you to update nuxt-og-image to version 6.8.0 or later.[/subscribe_to_unlock_form]
CVE-2026-61793 with a CVSS score of 6.9 is a server-side request forgery (SSRF) vulnerability in nuxt-og-image that allows unauthenticated remote attackers to make arbitrary HTTP requests from the Nuxt server by supplying attacker-controlled font URLs through the /_og/d/** endpoint. The vulnerable implementation lacks URL validation and permits requests to internal services including loopback addresses private networks cloud metadata endpoints and internal administrative interfaces. A response-status side channel can also allow attackers to identify reachable internal services and open ports.
We recommend you to update nuxt-og-image to version 6.8.0 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]