Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: server-side (1 article)Clear

Critical Next.js ImageResponse flaw enables server code execution through crafted SVG input

Vercel patched a critical flaw in Next.js ImageResponse, the feature that generates Open Graph and social preview images, that can let attackers run code on the server. Tracked as CVE-2026-94545 and rated 9.5, it affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the default Node.js runtime, and is fixed in 16.3.6. The Edge runtime and Next.js 15 are not affected. ImageResponse uses the Satori library to convert layouts into SVG before rendering, and apps are exposed when they pass attacker-controlled values, such as text from a request URL, into SVG content, attributes, or styles. As of disclosure there were no public exploits or reports of attacks.

Check
Search code for ImageResponse imported from next/og in route handlers and opengraph-image files, then upgrade affected apps to Next.js 16.3.6.
Affected
Next.js apps on 16.2.0 through 16.3.5 using Node runtime ImageResponse with attacker-controlled values in generated SVG can be driven to server code execution.
Fix
Update to Next.js 16.3.6, avoid placing request-derived values into image content, and consider the Edge runtime where feasible for image generation.