5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether nuxt-og-image is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-61793
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
LOW 3.7
CVE-2026-44589
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
MEDIUM 6.1
CVE-2026-34405
Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes
UNKNOWN
CVE-2026-34404
Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions
MEDIUM 5.3
GHSA-pqhr-mp3f-hrpp
Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes