Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
Unauthenticated attackers can execute code on Next.js 16.2.0–16.3.5 servers via crafted SVG in ImageResponse.
A flaw tracked as GHSA-vcvr-r3jv-pc5j in Next.js ImageResponse can let unauthenticated remote attackers execute code by supplying crafted values that are rendered into SVG. It affects the Node.js next/og path in versions 16.2.0 through 16.3.5 when untrusted input reaches SVG content, attributes, or styles via Satori. Vercel released Next.js 16.3.6, with 15.5.26 as related hardening for the 15.x line, and Satori 0.33.5 includes the library fix. Edge ImageResponse and applications that never insert attacker-controlled data are out of scope, and the report does not cite in-the-wild exploitation.