<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:02:44.898780+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05816</id>
    <title>bdu:2026-05816</title>
    <updated>2026-10-03T14:02:44.958072+00:00</updated>
    <content>bdu:2026-05816</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278556</id>
    <title>EUVD-2026-278556</title>
    <updated>2026-10-03T14:02:44.958109+00:00</updated>
    <content>EUVD-2026-278556</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34405</id>
    <title>fkie_cve-2026-34405</title>
    <updated>2026-10-03T14:02:44.958123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mg36-wvcr-m75h</id>
    <title>GHSA-mg36-wvcr-m75h — Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes</title>
    <updated>2026-10-03T14:02:44.958155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nuxt-og-image</p>
<p>**Product:** Nuxt OG Image 
**Version:** 6.1.2
**CWE-ID:** [CWE-79](https://cwe.mitre.org/data/definitions/79.html): Improper Neutralization of Input During Web Page Generation
**Description:** Incorrect parsing of GET parameters leads to the possibility of HTML injection and JavaScript code injection.
**Impact:** Client-Side JavaScript Execution
**Exploitation condition:** An external user
**Mitigation:** Correct the logic of parsing GET parameters and their subsequent implementation into the generated page.
**Researcher:** Dmitry Prokhorov (Positive Technologies)</p>
<p>## Research 
During the analysis of the nuxt-og-image package, which is shipped with the nuxt-seo package, a zero‑day vulnerability was discovered.
This research revealed that the image‑generation component by the URI: `/_og/d/` (and, in older versions, `/og-image/`) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. The vulnerability was reproduced using the standard configuration and the default templates.</p>
<p>_Listing 1. The content of the configuration file `nuxt.config.ts`_ 
```
export default defineNuxtConfig({
  modules: ['nuxt-og-image'],
  devServer: {
    host: 'web-test.local',
    port: 3000
  },
  site: {
    url: 'http://web-test.local:3000',
  },
  ogImage: {
    fonts: [
      'Inter:400', 
      'Inter:700'
    ],
  }
})
```</p>
<p>## Vulnerability reproduction
To demonstrate the proof‑of‑concept, follow the URI: `/_og/d/og.html?width=1000&amp;height=1000&amp;onmouseo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mg36-wvcr-m75h"/>
  </entry>
</feed>
