Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
Unauthenticated attackers can execute code on Next.js 16.2.0–16.3.5 servers via crafted SVG in ImageResponse.
A flaw tracked as GHSA-vcvr-r3jv-pc5j in Next.js ImageResponse can let unauthenticated remote attackers execute code by supplying crafted values that are rendered into SVG. It affects the Node.js next/og path in versions 16.2.0 through 16.3.5 when untrusted input reaches SVG content, attributes, or styles via Satori. Vercel released Next.js 16.3.6, with 15.5.26 as related hardening for the 15.x line, and Satori 0.33.5 includes the library fix. Edge ImageResponse and applications that never insert attacker-controlled data are out of scope, and the report does not cite in-the-wild exploitation.
- Unauthenticated RCE affects Next.js 16.2.0 through 16.3.5 Node.js ImageResponse.
- Attacker-controlled SVG content, attributes, or styles are not properly escaped.
- Edge ImageResponse and apps that never embed untrusted input are unaffected.
- Upgrade to Next.js 16.3.6; 15.5.26 hardens 15.x; Satori fixed in 0.33.5.
Full article507 words · extracted from gbhackers.com · click to collapse
A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets rendered into SVG content during dynamic image generation.
This issue, tracked as GHSA-vcvr-r3jv-pc5j, affects the Node.js implementation of ImageResponse in the next/og package.
The flaw impacts Next.js versions 16.2.0 to 16.3.5. Vercel has released Next.js version 16.3.6 to address this issue. In contrast, the 15.x release line has received version 15.5.26 as a related security-hardening update.
Next.js ImageResponse Vulnerability
ImageResponse is commonly used to generate Open Graph images, social media preview cards, and other server-generated graphics from JSX and CSS. The vulnerable Node.js path processes output through Satori, a library that converts JSX-like layout data into SVG before an image is produced.
The underlying problem stems from improper escaping of values placed into generated SVG output. An application becomes exposed when it accepts attacker-controlled data, such as a query parameter, API value, form field, or URL-derived string, and embeds it in SVG content, an attribute, or a style processed by Node.js ImageResponse.
Crafted content could then be interpreted as SVG markup rather than inert text, creating conditions that can lead to remote code execution.
A vulnerable implementation might resemble the following pattern:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
}
In this scenario, an attacker may send a specifically crafted value parameter to an internet-facing image endpoint. If the application runs the affected Node.js implementation and passes that input into SVG generation, the request could reach the vulnerable rendering chain.
Not every Next.js application using ImageResponse is vulnerable. The advisory states that the flaw applies only under specific conditions:
- The application uses Next.js versions 16.2.0 through 16.3.5.
- The `next/og` image generation runs through the Node.js implementation of ImageResponse.
- Untrusted input reaches SVG content, attributes, or CSS-style values.
- The image-generation route is accessible to an attacker over the network.
Applications using the Edge ImageResponse implementation are not affected. Deployments that never insert attacker-controlled data into SVG output are also outside the identified vulnerable scope.
Organizations should immediately upgrade affected Next.js deployments to version 16.3.6 and redeploy applications. Teams should prioritize reviewing Open Graph image endpoints, route handlers, and dynamic preview-image generators that read request-controlled values.
Where patching cannot occur immediately, developers should ensure that untrusted input is not supplied to SVG content, attributes, or styles rendered by Node.js ImageResponse.
Satori itself was patched in version 0.33.5, and its advisory warns that no complete workaround exists for direct Satori usage beyond upgrading and avoiding attacker-controlled rendered content.
Given the potential for server-side code execution without authentication or user interaction, exposed `next/og` image-generation endpoints should be treated as a high-priority patching target.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.