Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
PatchNext.jsOur summary
Vercel has patched CVE-2026-94545, a critical Next.js vulnerability that can allow server-side code execution when Node.js ImageResponse processes attacker-controlled values in generated SVG content. The issue affects Next.js 16.2.0 through 16.3.5; Next.js 15 and the Edge implementation of ImageResponse are not affected. Organizations should upgrade to Next.js 16.3.6, while developers using Satori directly should update to version 0.33.5.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.