Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
- ID
- 27619
- Status
- summarized
- Published
- 23 Sep 2026, 3:04 PM
- Fetched
- 23 Sep 2026, 3:29 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 9.0
- Created
- 23 Sep 2026, 3:35 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
A critical RCE vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js's ImageResponse feature allows attackers to execute server code via crafted SVG inputs when attacker-controlled values are passed into the image. The flaw affects Next.js 16.2.0 through 16.3.5 on the Node.js runtime and was fixed in version 16.3.6 on September 22, 2026.
Why it matters
If your app uses Next.js 16.2.0–16.3.5 and passes user-controlled data (like request URLs) into next/og ImageResponse on the Node.js runtime, you must immediately upgrade to 16.3.6 or strip attacker-controlled values from SVG content, attributes, and styles to prevent server takeover.
Discussion angle
How to audit Next.js route handlers and opengraph-image files for unsafe user input rendering, and the limitations of relying on npm audit, which failed to flag this vulnerability.