Critical Next.js RCE (CVSS 9.5): attacker-controlled SVG in next/og can execute server code

evilsocket · x · 2026-09-23

Vercel disclosed a critical RCE in the Node.js implementation of ImageResponse from next/og (CVE-2026-94545, CVSS 9.5).

Related event: Critical RCE Flaw (CVSS 9.5) Found in Next.js next/og(2 posts)→

Original post →

More from Safety

Safety channel →