Next.js 16.2.0–16.3.5 Node.js ImageResponse RCE via Crafted SVG Input (GHSA-vcvr-r3jv-pc5j / CVE-2026-94545)
Unauthenticated remote code execution is possible in Next.js 16.2.0–16.3.5 when the Node.js next/og ImageResponse inserts attacker-controlled SVG content, attributes, or styles; fixed in Next.js 16.3.6 and upstream Satori 0.33.5.
GitHub advisory GHSA-vcvr-r3jv-pc5j warns that Next.js 16.2.0 through 16.3.5 can allow remote code execution when the Node.js next/og ImageResponse implementation inserts attacker-controlled data into SVG content, attributes, or styles without proper escaping. The root cause is an upstream flaw in Satori 0.0.27 through 0.33.4, tracked as CVE-2026-94545 and patched in Satori 0.33.5. Vercel shipped the fix in Next.js 16.3.6; per GBHackers, Next.js 15.5.26 was also released as related hardening for the 15.x line. The Edge ImageResponse implementation is not affected, and applications that never insert untrusted data into ImageResponse are out of scope. GitHub rated the issue critical under CVSS v4 for unauthenticated network exploitation. Neither source reports in-the-wild exploitation, and the two reports agree on all core facts (affected versions, component, and fix versions).
- Advisory GHSA-vcvr-r3jv-pc5j; upstream Satori flaw tracked as CVE-2026-94545, affecting Satori 0.0.27 through 0.33.4 and fixed in Satori 0.33.5.
- Affects Next.js 16.2.0 through 16.3.5 via the Node.js next/og ImageResponse implementation only; the Edge implementation is not affected.
- Unauthenticated remote attackers can achieve code execution by supplying crafted values rendered into SVG content, attributes, or styles that are not properly escaped.
- Fixes: upgrade to Next.js 16.3.6; Satori 0.33.5 contains the library fix; GBHackers additionally reports Next.js 15.5.26 as hardening for the 15.x line.
- GitHub rated the vulnerability critical under CVSS v4 due to unauthenticated network exploitation (Cyber Security News).
- No in-the-wild exploitation is reported by either source.
- Applications that never insert attacker-controlled data into ImageResponse are unaffected.
Coverage timelineoldest first · each row is one article
- · 7d agoNode.js ImageResponse Implementation Vulnerability Enables Remote Code Execution
Cyber Security News· 76
Next.js 16.2.0–16.3.5 Node.js ImageResponse can allow RCE via unsanitized SVG input; fixed in 16.3.6.
- · 7d agoNext.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
GBHackers· 76
Unauthenticated attackers can execute code on Next.js 16.2.0–16.3.5 servers via crafted SVG in ImageResponse.
Vulnerabilities in this storyAll →
- CVE-2026-945455.3<1%Improper Output Escaping in Satori SVG Generator Exposes Next.js OG Image Pipelinespublished · Vercel Satori PoC ×5
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94545 | Improper Output Escaping in Satori SVG Generator Exposes Next.js OG Image Pipelines |