Next.js ImageResponse Flaw CVE-2026-94545 Can Enable Code Execution
Vercel patched Next.js CVE-2026-94545, a critical ImageResponse bug that can run server code from crafted SVG input on Node.js.
Vercel patched CVE-2026-94545 in Next.js ImageResponse (next/og) on the Node.js runtime, affecting 16.2.0 through 16.3.5 and fixed in 16.3.6. The Hacker News reports CVSS 9.5 in Vercel's advisory and says attacker-controlled values can reach Satori's SVG output unescaped and lead to server code execution via downstream libraries; Satori 0.33.5 fixes that bug, while Satori's advisory rates it moderate at CVSS 5.3. Cyber Security News tracks the same issue as GHSA-vcvr-r3jv-pc5j and describes it as a critical CVSS v4 flaw that can allow unauthenticated remote code execution when an application embeds attacker-controlled data in SVG elements, attributes, or styles, but gives no numeric score. Both say the Edge runtime is unaffected and that apps which never place untrusted values in SVG content are not affected; The Hacker News also says Next.js 15 is unaffected, with hardening in 15.5.26. As of September 23, 2026, neither outlet reported public attacks or exploit code, and The Hacker News said npm audit did not flag affected versions. A stated workaround is to keep attacker-controlled values out of SVG content, attributes, and styles.
- CVE-2026-94545 (GHSA-vcvr-r3jv-pc5j) affects Next.js ImageResponse in next/og on the Node.js runtime, versions 16.2.0 through 16.3.5.
- The Hacker News cites CVSS 9.5 (critical) in Vercel's advisory and CVSS 5.3 (moderate) in Satori's; Cyber Security News calls it critical under CVSS v4 with no numeric score.
- Fixed in Next.js 16.3.6; Satori 0.33.5 fixes the underlying escaping bug, and Next.js 15.5.26 adds hardening.
- The Edge runtime and Next.js 15 are unaffected; apps that never place untrusted values in SVG content, attributes, or styles are not affected.
- Cyber Security News says an unauthenticated remote attacker can trigger code execution during image generation if attacker-controlled SVG data is embedded.
- As of September 23, 2026, neither source reported public attacks or exploit code, and The Hacker News said npm audit did not flag affected versions.
Coverage timelineoldest first · each row is one article
- · 4d agoCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
The Hacker News· 62
Vercel patched critical Next.js ImageResponse flaw CVE-2026-94545 (CVSS 9.5) allowing server code execution via crafted SVG input; no attacks reported yet.
- · 3d agoCritical NEXT.JS Flaw Allows Remote Code Execution Via Weaponized SVG File
Cyber Security News· 73
Next.js CVE-2026-94545 can allow unauthenticated remote code execution through malicious SVG in ImageResponse.
Vulnerabilities in this storyAll →
- published — PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94545 | NVD description · AI analysis pending | — | — | PoC ×2 | — |