{"id":"GHSA-mg36-wvcr-m75h","summary":"Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes","details":"**Product:** Nuxt OG Image \n**Version:** 6.1.2\n**CWE-ID:** [CWE-79](https://cwe.mitre.org/data/definitions/79.html): Improper Neutralization of Input During Web Page Generation\n**Description:** Incorrect parsing of GET parameters leads to the possibility of HTML injection and JavaScript code injection.\n**Impact:** Client-Side JavaScript Execution\n**Exploitation condition:** An external user\n**Mitigation:** Correct the logic of parsing GET parameters and their subsequent implementation into the generated page.\n**Researcher:** Dmitry Prokhorov (Positive Technologies)\n\n## Research \nDuring the analysis of the nuxt-og-image package, which is shipped with the nuxt-seo package, a zero‑day vulnerability was discovered.\nThis research revealed that the image‑generation component by the URI: `/_og/d/` (and, in older versions, `/og-image/`) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. The vulnerability was reproduced using the standard configuration and the default templates.\n\n\n_Listing 1. The content of the configuration file `nuxt.config.ts`_ \n```\nexport default defineNuxtConfig({\n  modules: ['nuxt-og-image'],\n  devServer: {\n    host: 'web-test.local',\n    port: 3000\n  },\n  site: {\n    url: 'http://web-test.local:3000',\n  },\n  ogImage: {\n    fonts: [\n      'Inter:400', \n      'Inter:700'\n    ],\n  }\n})\n```\n\n## Vulnerability reproduction\nTo demonstrate the proof‑of‑concept, follow the URI: `/_og/d/og.html?width=1000&height=1000&onmouseover=alert(document.cookie)&autofocus`\nThe injected parameters `onmouseover=alert(document.cookie)` and `autofocus` are treated as attributes and are inserted directly into the generated HTML page.\n\n\n_Listing 2. HTTP-request example_\n```\nGET /_og/d/og.html?width=1000&height=1000&onmouseover=alert(document.cookie) HTTP/1.1\nHost: web-test.local:3000\n```\n\n_Figure 1. The injected attribute in the HTML body_\n\u003cimg width=\"974\" height=\"670\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d442c235-71a5-4da9-a963-8cf4b8614745\" /\u003e\n\n_Figure 2. JavaScript code execution_\n\u003cimg width=\"974\" height=\"291\" alt=\"image\" src=\"https://github.com/user-attachments/assets/01579f19-8e80-4fae-8516-5903370ee6d8\" /\u003e\n\n\n## Credits\nResearcher: Dmitry Prokhorov (Positive Technologies)","aliases":["CVE-2026-34405"],"modified":"2026-04-06T16:48:05.996343Z","published":"2026-03-31T23:27:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-31T23:27:03Z","nvd_published_at":"2026-03-31T22:16:18Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nuxt-modules/og-image/security/advisories/GHSA-mg36-wvcr-m75h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34405"},{"type":"PACKAGE","url":"https://github.com/nuxt-modules/og-image"}],"affected":[{"package":{"name":"nuxt-og-image","ecosystem":"npm","purl":"pkg:npm/nuxt-og-image"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.2.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mg36-wvcr-m75h/GHSA-mg36-wvcr-m75h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}