Critical Next.js RCE (CVSS 9.5): attacker-controlled SVG in next/og can execute server code
evilsocket · x · 2026-09-23
Vercel disclosed a critical RCE in the Node.js implementation of ImageResponse from next/og (CVE-2026-94545, CVSS 9.5).
- Affects Next.js >=16.2.0 <16.3.6; fixed in 16.3.6
- Exploitable over the network with no auth or user interaction when attacker-controlled values reach SVG content, attributes or styles (e.g. query params rendered into an OG image)
- The Edge ImageResponse implementation is not affected; apps that never put untrusted data into SVG are safe
- Workaround: if you can't upgrade immediately, stop passing attacker-controlled values into the Node.js ImageResponse SVG
Related event: Critical RCE Flaw (CVSS 9.5) Found in Next.js next/og(2 posts)→
More from Safety
- AI's real risks are boring: proxy optimization, agentic backdoors, power concentration — AryHHAry · 2026-09-23
- Anthropic Report Accuses 7 Chinese AI Firms of Gray-Market Distillation and Serving Claude as Their Own — DeepLearningAI · 2026-09-23
- Sam Altman to pitch global AI standards at the UN, Amodei joins by video — TorturedPoet30 · 2026-09-23
- Runway AI Summit lineup: AI diplomacy and US rulemaking sessions revealed — runwayml · 2026-09-23
- Genome Language Models Learn to "Think in DNA" as Bio-Security Arms Race Heats Up — Latent Space · 2026-09-23
- Frontier models are flooding CVE queues — 90-day disclosure windows must shrink to 30 — chrisrohlf · 2026-09-23