Critical Next.js RCE: CVE-2026-94545 hits next/og ImageResponse via Satori SVG escaping flaw
evilsocket · x · 2026-09-23
CVE-2026-94545 is a critical-severity RCE in Next.js's next/og ImageResponse, caused by improper SVG escaping in Satori (CWE-116). Versions >=16.2.0 <16.3.6 are affected; fixed in 16.3.6.
Pruva published a verified, runnable reproduction: the full exploit chain reaches the target end-to-end on the real production code path, with the agent-driven reproduction taking 84 minutes, 476 tool calls, and $17.73 of spend, complete with sandbox proof and artifacts. Developers should upgrade to 16.3.6 immediately.
Related event: Critical RCE flaw in Next.js next/og scores 9.5, fixed in 16.3.6(3 posts)→
More from coding & agent
- Harvard, Andrew Ng and Karpathy Teach AI Engineering Free: A 9-Step Learning Path — mdancho84 · 2026-09-23
- Cookie banners vs agents: X user shows Europe's web friction makes AI agents look superhuman — jeff_weinstein · 2026-09-23
- New ComfyUI nodes let you mask any video area and insert characters — roychodraws · 2026-09-23
- Shopping agents shouldn't delete shared ingredients when you cancel one meal — Electrical-Yard-287 · 2026-09-23
- From 1 Month of Runway to YC: Founder Sold Computer-Use 'AI Employees' on Orgo — nick_linck · 2026-09-23
- New Claude Opus Spontaneously Uses Temp Symlinks to Fix Rust Image Pipeline — generativist · 2026-09-23