Next.js ImageResponse Flaw Exposes Server Code Execution
Vercel fixed CVE-2026-94545 in Next.js 16.3.6 after finding that attacker-controlled values in ImageResponse could be interpreted as SVG on the default Node.js runtime, creating a path to server-side code execution. The issue affects Next.js 16.2.0 through 16.3.5; Next.js 15 and the Edge runtime are not affected.
ImageResponse uses Satori to turn layout into SVG before producing the final image. If request-derived text is allowed into SVG content, attributes, or styles, the renderer can treat it as structure instead of plain text, so a feature meant for previews can reach the server process with attacker influence.
For teams using next/og or route handlers that reflect request input, the exposure sits in the rendering layer, not in the image file itself. The remaining question is which deployments actually pass user-controlled values into that SVG path, because that is what turns a formatting feature into a code-execution risk.
Next.js: PoC pubblico per lo sfruttamento della CVE-2026-94545
Disponibile Proof of Concept (PoC) per lo sfruttamento della vulnerabilità CVE-2026-94545 – già sanata dal vendor – presente in next/og ImageResponse di Next.js.