Next.js flaw in next/og ImageResponse allows remote code execution: upgrade to 16.3.6
EditorialBy TrustList Editorial
Vercel’s advisory of 30 September 2026 says the Node.js ImageResponse in next/og, in Next.js 16.2.0 up to 16.3.6, can allow remote code execution when attacker-controlled values reach SVG content. Upgrade to 16.3.6.
About Next.js flaw in next/og ImageResponse allows remote code execution: upgrade to 16.3.6
Next.js flaw in next/og ImageResponse allows remote code execution: upgrade to 16.3.6
30 September 2026 — The Next.js maintainers published a security advisory on 30 September 2026, GHSA-vcvr-r3jv-pc5j, rated critical. It concerns the Node.js implementation of ImageResponse from next/og, the API Next.js applications use to generate images such as social-media preview cards. The advisory says it "is affected by an upstream vulnerability. This can lead to remote code execution." Italy's national cyber agency, ACN, published an alert the same day, tracking it as CVE-2026-94545 and reporting that proof-of-concept exploit code is public.
Who is affected
- Versions: Next.js 16.2.0 and later, before 16.3.6. The fix is in 16.3.6.
- Condition: an application is affected when it passes attacker-controlled values into SVG content, attributes or styles during image generation. The advisory's example is a route that takes a value from the URL query string and puts it into an SVG title rendered by
ImageResponse. - Not affected: applications using the Edge
ImageResponseimplementation, and applications that do not pass attacker-controlled values into SVG content, attributes or styles.
ACN attributes the problem to the Satori library that next/og uses to build SVG images: crafted input can alter the SVG that is processed and, under certain conditions, run arbitrary code on the server.
Why it matters
Dynamic Open Graph images are common in marketing sites, e-commerce, documentation and SaaS products built on Next.js, and they are often built from values in the URL, such as a product name, a user's handle or a page title. Code running on the server that renders them can reach environment variables, secrets and internal services. With exploit code public, exposed routes can be found and attacked quickly.
Workaround
If upgrading at once is not possible, the advisory's workaround is to stop passing attacker-controlled values into SVG content, attributes or styles rendered by the Node.js ImageResponse.
What to do
- Upgrade Next.js to 16.3.6 in every application on 16.2 or later, and redeploy.
- Search your code for
next/ogandImageResponse, and list the routes that build images from request parameters. - Until patched, validate or escape any request-supplied value before it reaches the image template, or switch those routes to the Edge runtime.
- Agencies and software vendors that build Next.js sites for clients should check every client project, not only their own.
Sources
Categories & features
- United States
- Cybersecurity
- Web Development
- JavaScript
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.