Vulnerabilities/

nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

Severity:
Low

Description

The isBlockedUrl() denylist introduced in [email protected] to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies, March 2026) is incomplete.

Recommendation

Update the nuxt-og-image package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nuxt-og-image
Anything's wrong? Let us know Last updated on May 15, 2026