Critical RCE Flaw (CVSS 9.5) Found in Next.js next/og

Vercel disclosed a critical RCE vulnerability (CVE-2026-94545, CVSS 9.5) in the Node.js ImageResponse of Next.js next/og, exploitable via SVG injection. The flaw, rooted in an upstream issue, is fixed in version 16.3.6.

2026-09-23 ~ 2026-09-23 · 2 related posts