Package impact
npm / nuxt-og-image
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-44589 | low | 3.7 | 3.7 | 20d ago | nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect) | |||
| CVE-2026-34405 | unknown | — | — | 2mo ago | Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes | |||
| CVE-2026-34404 | unknown | — | — | 2mo ago | Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions |