A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets rendered into SVG content during dynamic image generation.
This issue, tracked as GHSA-vcvr-r3jv-pc5j, affects the Node.js implementation of ImageResponse in the next/og package.
The flaw impacts Next.js versions 16.2.0 to 16.3.5. Vercel has released Next.js version 16.3.6 to address this issue. In contrast, the 15.x release line has received version 15.5.26 as a related security-hardening update.
ImageResponse is commonly used to generate Open Graph images, social media preview cards, and other server-generated graphics from JSX and CSS. The vulnerable Node.js path processes output through Satori, a library that converts JSX-like layout data into SVG before an image is produced.
The underlying problem stems from improper escaping of values placed into generated SVG output. An application becomes exposed when it accepts attacker-controlled data, such as a query parameter, API value, form field, or URL-derived string, and embeds it in SVG content, an attribute, or a style processed by Node.js ImageResponse.
Crafted content could then be interpreted as SVG markup rather than inert text, creating conditions that can lead to remote code execution.
A vulnerable implementation might resemble the following pattern:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
} In this scenario, an attacker may send a specifically crafted value parameter to an internet-facing image endpoint. If the application runs the affected Node.js implementation and passes that input into SVG generation, the request could reach the vulnerable rendering chain.
Not every Next.js application using ImageResponse is vulnerable. The advisory states that the flaw applies only under specific conditions:
Applications using the Edge ImageResponse implementation are not affected. Deployments that never insert attacker-controlled data into SVG output are also outside the identified vulnerable scope.
Organizations should immediately upgrade affected Next.js deployments to version 16.3.6 and redeploy applications. Teams should prioritize reviewing Open Graph image endpoints, route handlers, and dynamic preview-image generators that read request-controlled values.
Where patching cannot occur immediately, developers should ensure that untrusted input is not supplied to SVG content, attributes, or styles rendered by Node.js ImageResponse.
Satori itself was patched in version 0.33.5, and its advisory warns that no complete workaround exists for direct Satori usage beyond upgrading and avoiding attacker-controlled rendered content.
Given the potential for server-side code execution without authentication or user interaction, exposed `next/og` image-generation endpoints should be treated as a high-priority patching target.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…