THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q8hw-4fvp-9rwv (medium) — Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

[GHSA] GHSA-q8hw-4fvp-9rwv (medium) — Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

highgithub_advisoriesPublished 2026-09-17

GHSA-q8hw-4fvp-9rwv Severity: medium CVE: CVE-2026-61793

Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

### Summary `nuxt-og-image` exposes an **unauthenticated HTTP endpoint** at `/_og/d/**` that base64url-decodes and `JSON.parse`s a `fonts` URL segment, then passes each `fonts[i].path` value directly into `fetch()` server-side **without any URL validation** (no scheme

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q8hw-4fvp-9rwv