
Critical Next.js ImageResponse Flaw Exposes Systems to Attacks

General Information:
Next.js is a popular web development framework built on top of React (primarily maintained and developed by Vercel) to help overcome the limitations of traditional React, making the creation of full-stack websites or web applications easier, faster, and more efficient.
Incident:
The vulnerability is identified as CVE-2026-94545 with a high CVSS score of 9.5, which allows an attacker to execute code on the server (Server Code Execution / RCE).
The problematic feature is ImageResponse (imported from next/og), which is commonly used to generate social media preview images such as Open Graph Images or opengraph-image files. ImageResponse utilizes an internal library called Satori to convert layout code into an SVG file before rendering it as a PNG image.
The vulnerability is caused by Satori's lack of strict escaping for certain text values. As a result, when user-supplied input (such as text or parameters sent from a Request URL) is inserted into SVG tags, attributes, or styles, the specially crafted value (Crafted SVG Input) is processed as SVG code instead of plain text. This malicious code is then passed on to other underlying libraries used by Next.js, opening a vector for dangerous code execution on the server.
The affected versions are Next.js versions 16.2.0 to 16.3.5 running on the Node.js runtime (Next.js version 15 is not affected by this RCE bug, but patch 15.5.26 was released for additional security).
Recommendations:
1. Update Next.js to version 16.3.6 using the command npm install next@16.3.6.
2. For those using the Satori library directly: update to version 0.33.5 or higher.
3. Inspect and avoid directly inserting user-controlled values, such as Query Strings from URLs, into the SVG content, attributes, or styles of ImageResponse on the Node.js runtime.
Reference:
•https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html