CVE-2026-44589: Nuxt-Modules Og-Image

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.2.5 to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies, March 2026) is incomplete. It has an incomplete IPv6 prefix list and is missing redirect re-validation. This vulnerability is fixed in 6.4.9.

Affected products

  • Nuxt-Modules Og-Image: from 6.2.5, before 6.4.9 (fixed in 6.4.9)

Published 2026-05-14. Last modified 2026-06-17.