Critical RCE (CVSS 9.5) found in Next.js next/og ImageResponse, patched in 16.3.6

jedisct1 · x · 2026-09-23

Vercel published advisory GHSA-vcvr-r3jv-pc5j: the Node.js ImageResponse implementation in next/og is affected by an upstream vulnerability that can lead to remote code execution, rated Critical with CVSS 9.5.

Original post →

More from Safety

Safety channel →