AI Weekly Malaysia

Back to items Summaries

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

ID
27619
Status
summarized
Published
23 Sep 2026, 3:04 PM
Fetched
23 Sep 2026, 3:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
9.0
Created
23 Sep 2026, 3:35 PM
Tags
Audience
developerssaas_startup_founders

What happened

A critical RCE vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js's ImageResponse feature allows attackers to execute server code via crafted SVG inputs when attacker-controlled values are passed into the image. The flaw affects Next.js 16.2.0 through 16.3.5 on the Node.js runtime and was fixed in version 16.3.6 on September 22, 2026.

Why it matters

If your app uses Next.js 16.2.0–16.3.5 and passes user-controlled data (like request URLs) into next/og ImageResponse on the Node.js runtime, you must immediately upgrade to 16.3.6 or strip attacker-controlled values from SVG content, attributes, and styles to prevent server takeover.

Discussion angle

How to audit Next.js route handlers and opengraph-image files for unsafe user input rendering, and the limitations of relying on npm audit, which failed to flag this vulnerability.

Top