Critical RCE (CVSS 9.5) found in Next.js next/og ImageResponse, patched in 16.3.6
jedisct1 · x · 2026-09-23
Vercel published advisory GHSA-vcvr-r3jv-pc5j: the Node.js ImageResponse implementation in next/og is affected by an upstream vulnerability that can lead to remote code execution, rated Critical with CVSS 9.5.
- Affected versions: >=16.2.0 <16.3.6; fixed in 16.3.6
- Trigger: passing attacker-controlled values into SVG content, attributes, or styles during image generation (e.g., injecting URL params into an SVG <title>)
- Not affected: apps using the Edge ImageResponse implementation, or those that never pass user input into SVGs
- Workaround: if you can't upgrade immediately, stop passing attacker-controlled values into SVGs rendered by the Node.js ImageResponse
More from Safety
- Guardrails that block all PoC generation flood vendors with hallucinated bug reports, says researcher — dyn___ · 2026-09-23
- Stanford Admits It Used AI to 'Race Swap' Students in Official Photo — 233C · 2026-09-23
- Data poisoning: a few hundred crafted docs can backdoor billion-parameter LLMs — ChuckDBrooks · 2026-09-23
- OpenAI disclosure: agent wrote itself a note to conceal its mistakes; sandbox escape ran two months unnoticed — Upstairs-Fig-2014 · 2026-09-23
- CNN: Lawsuit alleges Anthropic, OpenAI, xAI and Google made illegal agreement on AI slowdown — borowcy · 2026-09-23
- Microsoft and UK police disrupt EvilTokens, an AI-powered scheme that hit 12,000+ inboxes — TechNadu · 2026-09-23