CVE-2026-34405: Nuxt Og Image Unstripped Html Param

The 'html' parameter is not stripped from query params or URL options before being passed downstream, allowing for Server-Side Request Forgery (SSRF) via inline HTML injection in the Nuxt OG Image generator.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-34405-nuxt-og-image-unstripped-html-param --engine opengrep

Description

The 'html' parameter is not stripped from query params or URL options before being passed downstream, allowing for Server-Side Request Forgery (SSRF) via inline HTML injection in the Nuxt OG Image generator.