<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:01:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05816</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05816</link>
      <description>bdu:2026-05816</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05816</guid>
    </item>
    <item>
      <title>EUVD-2026-278556</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278556</link>
      <description>EUVD-2026-278556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278556</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34405</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34405</link>
      <description>&lt;p&gt;Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34405</guid>
    </item>
    <item>
      <title>GHSA-mg36-wvcr-m75h — Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mg36-wvcr-m75h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt-og-image&lt;/p&gt;
&lt;p&gt;**Product:** Nuxt OG Image 
**Version:** 6.1.2
**CWE-ID:** [CWE-79](https://cwe.mitre.org/data/definitions/79.html): Improper Neutralization of Input During Web Page Generation
**Description:** Incorrect parsing of GET parameters leads to the possibility of HTML injection and JavaScript code injection.
**Impact:** Client-Side JavaScript Execution
**Exploitation condition:** An external user
**Mitigation:** Correct the logic of parsing GET parameters and their subsequent implementation into the generated page.
**Researcher:** Dmitry Prokhorov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research 
During the analysis of the nuxt-og-image package, which is shipped with the nuxt-seo package, a zero‑day vulnerability was discovered.
This research revealed that the image‑generation component by the URI: `/_og/d/` (and, in older versions, `/og-image/`) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. The vulnerability was reproduced using the standard configuration and the default templates.&lt;/p&gt;
&lt;p&gt;_Listing 1. The content of the configuration file `nuxt.config.ts`_ 
```
export default defineNuxtConfig({
  modules: [&amp;#39;nuxt-og-image&amp;#39;],
  devServer: {
    host: &amp;#39;web-test.local&amp;#39;,
    port: 3000
  },
  site: {
    url: &amp;#39;http://web-test.local:3000&amp;#39;,
  },
  ogImage: {
    fonts: [
      &amp;#39;Inter:400&amp;#39;, 
      &amp;#39;Inter:700&amp;#39;
    ],
  }
})
```&lt;/p&gt;
&lt;p&gt;## Vulnerability reproduction
To demonstrate the proof‑of‑concept, follow the URI: `/_og/d/og.html?width=1000&amp;amp;height=1000&amp;amp;onmouseo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt-og-image&lt;/p&gt;
&lt;p&gt;**Product:** Nuxt OG Image 
**Version:** 6.1.2
**CWE-ID:** [CWE-79](https://cwe.mitre.org/data/definitions/79.html): Improper Neutralization of Input During Web Page Generation
**Description:** Incorrect parsing of GET parameters leads to the possibility of HTML injection and JavaScript code injection.
**Impact:** Client-Side JavaScript Execution
**Exploitation condition:** An external user
**Mitigation:** Correct the logic of parsing GET parameters and their subsequent implementation into the generated page.
**Researcher:** Dmitry Prokhorov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research 
During the analysis of the nuxt-og-image package, which is shipped with the nuxt-seo package, a zero‑day vulnerability was discovered.
This research revealed that the image‑generation component by the URI: `/_og/d/` (and, in older versions, `/og-image/`) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. The vulnerability was reproduced using the standard configuration and the default templates.&lt;/p&gt;
&lt;p&gt;_Listing 1. The content of the configuration file `nuxt.config.ts`_ 
```
export default defineNuxtConfig({
  modules: [&amp;#39;nuxt-og-image&amp;#39;],
  devServer: {
    host: &amp;#39;web-test.local&amp;#39;,
    port: 3000
  },
  site: {
    url: &amp;#39;http://web-test.local:3000&amp;#39;,
  },
  ogImage: {
    fonts: [
      &amp;#39;Inter:400&amp;#39;, 
      &amp;#39;Inter:700&amp;#39;
    ],
  }
})
```&lt;/p&gt;
&lt;p&gt;## Vulnerability reproduction
To demonstrate the proof‑of‑concept, follow the URI: `/_og/d/og.html?width=1000&amp;amp;height=1000&amp;amp;onmouseo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mg36-wvcr-m75h</guid>
    </item>
  </channel>
</rss>
