Critical RCE Flaw (CVSS 9.5) Found in Next.js next/og
Vercel disclosed a critical RCE vulnerability (CVE-2026-94545, CVSS 9.5) in the Node.js ImageResponse of Next.js next/og, exploitable via SVG injection. The flaw, rooted in an upstream issue, is fixed in version 16.3.6.
2026-09-23 ~ 2026-09-23 · 2 related posts
- Critical RCE (CVSS 9.5) found in Next.js next/og ImageResponse, patched in 16.3.6 — jedisct1 · 2026-09-23
- Critical Next.js RCE (CVSS 9.5): attacker-controlled SVG in next/og can execute server code — evilsocket · 2026-09-23