Critical Next.js RCE: CVE-2026-94545 hits next/og ImageResponse via Satori SVG escaping flaw

evilsocket · x · 2026-09-23

CVE-2026-94545 is a critical-severity RCE in Next.js's next/og ImageResponse, caused by improper SVG escaping in Satori (CWE-116). Versions >=16.2.0 <16.3.6 are affected; fixed in 16.3.6.

Pruva published a verified, runnable reproduction: the full exploit chain reaches the target end-to-end on the real production code path, with the agent-driven reproduction taking 84 minutes, 476 tool calls, and $17.73 of spend, complete with sandbox proof and artifacts. Developers should upgrade to 16.3.6 immediately.

Related event: Critical RCE flaw in Next.js next/og scores 9.5, fixed in 16.3.6(3 posts)→

Original post →

More from coding & agent

coding & agent channel →