Next.js next/og RCE CVE-2026-94545: one unauthenticated POST yields a shell on default prod setups
jedisct1 · x · 2026-09-30
- Security team EQSTLab disclosed CVE-2026-94545 (CVSS 9.5): an unauthenticated RCE in Next.js's next/og Open Graph image endpoint, with a public PoC on GitHub (exploit.py plus a reproducible Docker environment).
- It hits the vendor-recommended production default: next/og on the Node.js runtime with sharp installed. A single unauthenticated POST executes commands on the server.
- Root cause: Satori renders JSX to SVG without escaping user-supplied text (CWE-116), letting attackers close the tag and inject their own SVG markup. The SVG is then rasterized by native libraries (libvips, librsvg, libxml2), corrupting memory; since Node ships non-PIE, a hardcoded ROP chain reliably lands execve.
- Unaffected paths: edge runtime or setups without sharp. The "Next.js is the new Fortigate" quip is circulating as a warning to audit internet-exposed apps on default configs.
More from coding & agent
- Claude-Powered SEO Content Pipeline Goes Viral — Then an SEO Vet Shares What Happens 3 Months Later — lilyraynyc · 2026-09-30
- NVIDIA open-sources ProRL Agent: rollout-as-a-service to fix RL training bottlenecks for LLM agents — burkov · 2026-09-30
- 100 autonomous AI agents are building a civilization in open-source sim CYMONIA — Positive-Captain-709 · 2026-09-30
- How a runaway agent loop almost burned $1,200 overnight, and the case for hard budget caps — MaverikSh · 2026-09-30
- Hugging Face datatrove 0.10.1 fixes empty-doc crashes and a silently ignored skip parameter — vanstriendaniel · 2026-09-30
- Arbor: open-source framework for AI agents doing autonomous long-horizon research — burkov · 2026-09-30